Home/Threat Actor/SideWinder
Threat Actor

SideWinder

sidewinder · india · active since 2012

SideWinder (Rattlesnake / T-APT-04 / APT-C-17 / RAZOR TIGER / BabyElephant / G0121) is an India-aligned cyber-espionage cluster active since 2012, widely assessed by multiple independent vendor research teams to operate in alignment with Indian state interests, responsible for sustained high-tempo collection against Pakistan military, Pakistan Strategic Plans Division, Chinese government and diplomatic targets, and Bangladesh, Sri Lanka, Nepal, Bhutan, Maldives, and Afghanistan, with notable 2022-2024 expansion into maritime and Southeast Asia targeting and the October 2024 Kaspersky disclosure of the previously-undocumented StealerBot modular post-exploitation framework substantially raising the assessed sophistication tier of the cluster.

india confidence: high 19 aliases MITRE ATT&CK G0121 ↗

Profile

SideWinder (also tracked as Rattlesnake, T-APT-04, APT-C-17, RAZOR TIGER, BabyElephant, HARDCORE NATIONALIST, and MITRE ATT&CK G0121) is an India-aligned cyber-espionage cluster active since at least 2012, characterized by sustained, high-tempo collection against Pakistan, Bangladesh, Sri Lanka, Nepal, Bhutan, Maldives, Afghanistan, and Chinese government, military, diplomatic, and maritime targets. The cluster was first publicly documented in 2018 under the SideWinder name (Kaspersky) and the T-APT-04 name (Chinese vendors)

earlier activity has been retroactively attributed back to ~2012 from code and infrastructure overlap. Attribution to India is the dominant assessment across multiple independent vendor research teams (Kaspersky GReAT, Group-IB, BlackBerry, BitDefender, AT&T Alien Labs, Trend Micro, SentinelOne, Cisco Talos, BitDefender, Cluster25, Cyfirma) based on consistent victimology and tradecraft signatures. No formal government attribution has been issued.

India has not acknowledged the cluster.

Pakistani officials have at times attributed SideWinder activity to India in domestic statements but no formal indictment or diplomatic attribution has occurred. The "India-aligned" framing in this record should be treated as suspected rather than confirmed. Operationally SideWinder is distinguished from many peer-tier regional clusters by its sustained operational tempo (among the highest-volume APT operations publicly tracked in South Asia), its rapid-iteration toolkit, and its disciplined multi-stage attack chain. Initial access is overwhelmingly via spear-phishing with weaponized Office documents (RTF exploiting CVE-2017-11882 Equation Editor remains a signature, alongside CVE-2017-8570, CVE-2017-0199, CVE-2018-0802, and more recent CVE-2022-26134 and CVE-2023-38831 against follow-on targets) and weaponized LNK files.

The signature multi-stage chain is: weaponized RTF/DOCX/LNK
  • HTA dropper executed via mshta.exe.
  • first-stage .NET loader.
  • second-stage modular implant (SideWinder RAT, Backslash backdoor, WarHawk, or, most recently, the StealerBot modular framework). The October 2024 Kaspersky disclosure of StealerBot, a previously-undocumented modular post-exploitation espionage framework with file collection, keylogging, screen capture, credential theft, RDP credential capture, persistence, and lateral-movement modules, substantially raised the assessed sophistication tier of the cluster. StealerBot had been used against high-value diplomatic and government targets throughout 2023-2024 before disclosure. Geographically the cluster's footprint has expanded notably since 2022: while Pakistan and Chinese targets remain the core focus (including persistent operations against Pakistan's Strategic Plans Division and atomic-energy / nuclear-research entities, among the most strategically consequential elements of the cluster's operational profile), 2022-2024 reporting from Group-IB, BitDefender, and SentinelOne has documented expansion into maritime and Southeast Asia targets, Indonesian, Filipino, Singaporean, Malaysian, Vietnamese, and Cambodian government and maritime / port / shipping targets, plus Middle Eastern (UAE, Saudi Arabia, Qatar) and East African (Djibouti) maritime entities. Lures themed to Indo-Pacific maritime cooperation, ASEAN diplomacy, port-development programs, and regional naval exercises. A few operational notes deserve attention in any reporting that touches SideWinder: First, the cluster sometimes overlaps with other India-aligned activity tracked as BitterAPT / APT-C-08 and DoNot Team / APT-C-35, which are widely treated as separate India-aligned clusters but have at times shared infrastructure or lure themes. Treat as adjacent but separate unless reporting explicitly identifies cross-cluster overlap. Second, like APT36 in the opposite direction, SideWinder's targeting profile against Pakistan and against Sikh / Kashmiri diaspora entities can confuse with separate state surveillance activity; toolkit and tradecraft are distinctively SideWinder. Third, attribution to India specifically, though dominant in vendor reporting, has not been confirmed by formal state attribution and should be presented as suspected.

Aliases

19
sidewinderside winderside_winderrattlesnakerazor tigerrazor_tigert-apt-04t_apt_04tapt04apt-c-17apt_c_17aptc17babyelephantbaby elephantbaby_elephanthardcore nationalisthardcore_nationalistatk 91g0121

Notable Campaigns

8
2024-2025Continued Operations and Toolkit Iteration (2024-2025)
2024Kaspersky StealerBot Framework Disclosure (October 2024)
2023-2025Strategic-Plans / Nuclear-Adjacent Targeting (2023-2025)
2022-2024Maritime and Southeast Asia Expansion (2022-2024)
2022BlackBerry WarHawk Disclosure (October 2022)
2020-2022Chinese Government and Diplomatic Targeting (2020-2022)
2019-2021Sustained Pakistan Military and Government Targeting (2019-2021)
2018Initial Public Disclosure (2018)

Attribution & Reporting

Attributed by
Kaspersky GReATGroup-IBTrend MicroBlackBerryBitDefenderAT&T Alien LabsCisco TalosMicrosoftSentinelOneQiAnXin RedDripQihoo 360360 Threat Intelligence CenterESETVolexityRecorded Future Insikt GroupCluster25CyfirmaCybleZscaler ThreatLabzPT Expert Security Center
Key reporting
reportKaspersky GReAT: APT Trends Report Q1 2018, First Public SideWinder Mention
reportKaspersky GReAT: APT Trends Report Q2 2020, SideWinder Maritime Pivot
reportKaspersky GReAT: Beyond the Surface, The Evolution and Expansion of the SideWinder APT Group (StealerBot Framework, October 2024)
reportGroup-IB: SideWinder APT, A Persistent Threat to South Asia (2022)
reportBlackBerry: WarHawk, The New Backdoor in the Arsenal of the SideWinder APT Group (October 2022)
reportBitDefender: SideWinder, The Wolves That Don't Howl (2020)
reportBitDefender: SideWinder APT Deepens Attacks Against Pakistani Targets, Targets Nuclear Energy (2024)
reportAT&T Alien Labs: SideWinder Uses Server-Side Polymorphism to Target Pakistan Military (2021)
reportCisco Talos: SideWinder Uses Targeted Network Attacks (2019)
reportTrend Micro: New APT Group SideWinder Uses Google Firebase (August 2022)
reportSentinelOne Labs: Wave of SideWinder Attacks Targets Maritime Facilities in Asia and the Middle East (July 2024)
reportCluster25: SideWinder APT, India-Aligned Cluster Profile
reportCyfirma: SideWinder APT Strikes (2023)
reportRecorded Future Insikt Group: SideWinder APT Tracking (multiple years)
reportPT Expert Security Center: SideWinder APT Analysis
reportQiAnXin / 360 Threat Intelligence Center: T-APT-04 Tracking Reports (Chinese-language, 2018-2022)
reportMalpedia Actor Profile: SideWinder
reportMITRE ATT&CK Group G0121, SideWinder

Operational

State sponsor

Suspected India-aligned advanced persistent threat group. The cluster has been characterized as India-aligned by multiple independent vendor research teams, Kaspersky GReAT, Group-IB, BlackBerry, BitDefender, AT&T Alien Labs Labs, Trend Micro, and AnchorYak / Volexity, based on consistent victimology (Pakistan government and military, Bangladesh, Sri Lanka, Nepal, Bhutan, Maldives, Afghanistan, Chinese government and military diplomatic targets), operational hours, and language artifacts. No formal government attribution has been issued by any state. India has neither acknowledged nor denied a relationship.

Pakistan has at times publicly attributed SideWinder activity to India in domestic statements but no formal indictment or state-issued diplomatic attribution has occurred. The "India-aligned" framing should be treated as suspected rather than confirmed.

Motivations
espionage, intelligence_gathering, military_intelligence, geopolitical_collection, maritime_intelligence, economic_intelligence
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)24/60 · 40%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASERPENT STEALERSERPENTSTEALERSIDE MONKEYSIDEARMSIDEMONKEYSIDEWINDER RATSTEALER BOTSTEALERBOT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin