logo

SideWinder APT: Futuristic Tactics & Techniques

ID: 5c8ec97c-d4c6-56cb-b1ba-f4705bae5d46

STIX ID: report--5c8ec97c-d4c6-56cb-b1ba-f4705bae5d46

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-05-09

Date Updated: 2026-07-16

...
...

Cyble Research documents a SideWinder APT campaign delivering malware through a CVE-2017-11882-exploiting Word document (Protocol.doc) and LNK files inside an archive (Audit_Observation2019.zip). The deployed components (Rekeywiz.exe and Duser.dll) enable EFS, perform ECDH-P256-based file encryption, create the mutex "Local\ba76e584-735b-45d5-ab75-7ecb8ec8f208", and communicate with C2 185.99.133.58; the report includes file MD5s, domains/IPs, and recommended mitigations such as disabling EFS and patching systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.