🌐Windshift
🌐 Windshift is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: Unknown. We map 14 detection use cases to this actor across 19 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
19Techniques
0IOCs
About this actor (MITRE)
[Windshift](https://attack.mitre.org/groups/G0112) is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.(Citation: SANS Windshift August 2018)(Citation: objective-see windtail1 dec 2018)(Citation: objective-see windtail2 jan 2019)
Known aliases
WindshiftBahamut
Top techniques
All other tracked techniques
T1036.001 · Invalid Code SignatureT1047 · Windows Management InstrumentationT1057 · Process DiscoveryT1059.005 · Visual BasicT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1189 · Drive-by CompromiseT1204.001 · Malicious LinkT1204.002 · Malicious FileT1518 · Software DiscoveryT1518.001 · Security Software DiscoveryT1547.001 · Registry Run Keys / Startup FolderT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.003 · Spearphishing via Service