🌐Sidewinder
🌐 Sidewinder is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 30 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
30Techniques
0IOCs
About this actor (MITRE)
[Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.(Citation: ATT Sidewinder January 2021)(Citation: Securelist APT Trends April 2018)(Citation: Cyble Sidewinder September 2020)
Known aliases
SidewinderT-APT-04Rattlesnake
Top techniques
All other tracked techniques
T1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036.005 · Match Legitimate Resource Name or LocationT1057 · Process DiscoveryT1059.001 · PowerShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1074.001 · Local Data StagingT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1105 · Ingress Tool TransferT1119 · Automated CollectionT1124 · System Time DiscoveryT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1218.005 · MshtaT1518 · Software DiscoveryT1518.001 · Security Software DiscoveryT1547.001 · Registry Run Keys / Startup FolderT1559.002 · Dynamic Data ExchangeT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1574.001 · DLLT1598.002 · Spearphishing AttachmentT1598.003 · Spearphishing Link