G0121: Sidewinder
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.[1][2][3]
Security context for executives and security teams
G0121: Sidewinder describes [Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.(Citation: ATT Sidewinder January 2021)(Citation: Securelist APT Trends April 2018)(Citation: Cyble Sidewinder September 2020)
Executive priority
G0121: Sidewinder is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0121: Sidewinder by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0121: Sidewinder appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Sidewinder
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.[1][2][3]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1203 | Exploitation for Client Execution | Sidewinder has exploited vulnerabilities to gain execution including CVE-2017-11882 and CVE-2020-0674.[1][3] |
| Enterprise | T1518.001 | Security Software DiscoverySub-technique | Sidewinder has used the Windows service |
| Enterprise | T1218.005 | MshtaSub-technique | Sidewinder has used |
| Enterprise | T1598.003 | Spearphishing LinkSub-technique | Sidewinder has sent e-mails with malicious links to credential harvesting websites.[1] |
| Enterprise | T1124 | System Time Discovery | Sidewinder has used tools to obtain the current system time.[1] |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | Sidewinder has sent e-mails with malicious links often crafted for specific targets.[1][3] |
| Enterprise | T1074.001 | Local Data StagingSub-technique | Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration.[1] |
| Enterprise | T1057 | Process Discovery | Sidewinder has used tools to identify running processes on the victim's machine.[1] |
| Enterprise | T1059.007 | JavaScriptSub-technique | Sidewinder has used JavaScript to drop and execute malware loaders.[1]CitationRewterz Sidewinder COVID-19 June 2020 |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.[1]CitationRewterz Sidewinder APT April 2020[3] |
| Enterprise | T1020 | Automated Exfiltration | Sidewinder has configured tools to automatically send collected files to attacker controlled servers.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | Sidewinder has used LNK files to download remote files to the victim's network.[1][3] |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | Sidewinder has added paths to executables in the Registry to establish persistence.CitationRewterz Sidewinder APT April 2020CitationRewterz Sidewinder COVID-19 June 2020[3] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | Sidewinder has used HTTP in C2 communications.[1]CitationRewterz Sidewinder APT April 2020CitationRewterz Sidewinder COVID-19 June 2020 |
| Enterprise | T1559.002 | Dynamic Data ExchangeSub-technique | Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer.CitationRewterz Sidewinder APT April 2020CitationRewterz Sidewinder COVID-19 June 2020 |
| Enterprise | T1083 | File and Directory Discovery | Sidewinder has used malware to collect information on files and directories.[1] |
| Enterprise | T1016 | System Network Configuration Discovery | Sidewinder has used malware to collect information on network interfaces, including the MAC address.[1] |
| Enterprise | T1598.002 | Spearphishing AttachmentSub-technique | Sidewinder has sent e-mails with malicious attachments that lead victims to credential harvesting websites.[1]CitationRewterz Sidewinder APT April 2020[3] |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | Sidewinder has used base64 encoding for scripts.[1]CitationRewterz Sidewinder APT April 2020 |
| Enterprise | T1059.001 | PowerShellSub-technique | Sidewinder has used PowerShell to drop and execute malware loaders.[1] |
| Enterprise | T1518 | Software Discovery | Sidewinder has used tools to enumerate software installed on an infected host.[1]CitationRewterz Sidewinder APT April 2020 |
| Enterprise | T1059.005 | Visual BasicSub-technique | Sidewinder has used VBScript to drop and execute malware loaders.[1] |
| Enterprise | T1082 | System Information Discovery | Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.[1]CitationRewterz Sidewinder COVID-19 June 2020 |
| Enterprise | T1119 | Automated Collection | Sidewinder has used tools to automatically collect system and network configuration information.[1] |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | Sidewinder has sent e-mails with malicious attachments often crafted for specific targets.[1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Sidewinder has named malicious files |
| Enterprise | T1204.001 | Malicious LinkSub-technique | Sidewinder has lured targets to click on malicious links to gain execution in the target environment.[1]CitationRewterz Sidewinder APT April 2020CitationRewterz Sidewinder COVID-19 June 2020[3] |
| Enterprise | T1204.002 | Malicious FileSub-technique | Sidewinder has lured targets to click on malicious files to gain execution in the target environment.[1]CitationRewterz Sidewinder APT April 2020CitationRewterz Sidewinder COVID-19 June 2020[3] |
| Enterprise | T1033 | System Owner/User Discovery | Sidewinder has used tools to identify the user of a compromised host.[1] |
| Enterprise | T1574.001 | DLLSub-technique | Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe.[1] |
Groups, software, and campaigns
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.2 | Current bundle | cd89d953f405… | ||
| 19.1 | 1.2 | Older bundle | c657657a4341… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]ATT Sidewinder January 2021
Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.
Open source URL - [2]Securelist APT Trends April 2018
Global Research and Analysis Team . (2018, April 12). APT Trends report Q1 2018. Retrieved January 27, 2021.
Open source URL - [3]Cyble Sidewinder September 2020
Cyble. (2020, September 26). SideWinder APT Targets with futuristic Tactics and Techniques. Retrieved January 29, 2021.
Open source URL - [4]Rattlesnake
(Citation: Cyble Sidewinder September 2020)
- [5]T-APT-04
(Citation: Cyble Sidewinder September 2020)
- [6]mitre-attackG0121Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
