THREAT_ACTOR · G0121
Sidewinder
Also known as: Sidewinder, T-APT-04, Rattlesnake
Profile
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.
MITRE ATT&CK ↗Techniques
30 ATT&CK techniques attributed to this actor.
T1016 System Network Configuration DiscoveryT1020 Automated ExfiltrationT1027.010 Command ObfuscationT1027.013 Encrypted/Encoded FileT1033 System Owner/User DiscoveryT1036.005 Match Legitimate Resource Name or LocationT1057 Process DiscoveryT1059.001 PowerShellT1059.005 Visual BasicT1059.007 JavaScriptT1071.001 Web ProtocolsT1074.001 Local Data StagingT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1105 Ingress Tool TransferT1119 Automated CollectionT1124 System Time DiscoveryT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1218.005 MshtaT1518 Software DiscoveryT1518.001 Security Software DiscoveryT1547.001 Registry Run Keys / Startup FolderT1559.002 Dynamic Data ExchangeT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1574.001 DLLT1598.002 Spearphishing AttachmentT1598.003 Spearphishing Link
Software
1 malware/tools attributed to this actor.
Koadic
Related corpus activity
10,341 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Sidewinder.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,341.