logo

WarHawk: New APT backdoor from SideWinder

ID: 27940a0c-bbf9-503f-a6e1-daf93c02a753

STIX ID: report--27940a0c-bbf9-503f-a6e1-daf93c02a753

Feed Name: Zscaler Security Research Blog

Threat Score
88/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz discovered and analyzed 'WarHawk', a new backdoor used by the SideWinder APT to target Pakistan via malicious ISO files containing LNK shortcuts; WarHawk implements four modules (download & execute, command execution, file manager info exfil, uploadFromC2), delivers Cobalt Strike loaders that use KernelCallbackTable process injection and a Pakistan Standard Time check to restrict execution, and communicates with C2 infrastructure (notably 146.190.235.137 and domains mimicking Pakistani agencies); the report includes technical behavioral analysis, stage-2 payload details, MITRE ATT&CK mappings, and IoCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.