PULSE NAME
SideWinder targets the maritime and nuclear sectors with an updated toolset
WHITE RAZOR TIGER AlienVault 2025-03-10 Modified: 2025-03-10
53
IOCs
HIGH VOLUME
The SideWinder APT group intensified its activities in the second half of 2024, targeting maritime infrastructures, logistics companies, and nuclear sectors across Asia, the Middle East, and Africa. The group updated its toolset, including improvements to its RTF exploit, JavaScript loader, and Backdoor Loader. SideWinder's infection chain begins with spear-phishing emails containing malicious DOCX files, exploiting CVE-2017-11882 to deliver a multi-stage payload. The group demonstrated agility in evading detection, often updating their tools within hours of being identified. Notable targets included government entities, military installations, and diplomatic missions, with an increased focus on maritime and nuclear-related organizations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
StealerBot Downloader Module Module Installer
Indicators of Compromise (11 / 53 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0216ffc6fb679bdf4ea6ee7051213c1e 2025-03-10
FileHash-MD5 313f9bbe6dac3edc09fe9ac081950673 2025-03-10
FileHash-MD5 3d9961991e7ae6ad2bae09c475a1bce8 2025-03-10
FileHash-MD5 433480f7d8642076a8b3793948da5efe 2025-03-10
FileHash-MD5 872c2ddf6467b1220ee83dca0e118214 2025-03-10
FileHash-MD5 a694ccdb82b061c26c35f612d68ed1c2 2025-03-10
FileHash-MD5 bd8043127abe3f5cfa61bd2174f54c60 2025-03-10
FileHash-MD5 d36a67468d01c4cb789cd6794fb8bc70 2025-03-10
FileHash-MD5 e0bce049c71bc81afe172cd30be4d2b7 2025-03-10
FileHash-MD5 e9726519487ba9e4e5589a8a5ec2f933 2025-03-10
FileHash-MD5 f42ba43f7328cbc9ce85b2482809ff1c 2025-03-10