PULSE NAME
SideWinder targets the maritime and nuclear sectors with an updated toolset
WHITE RAZOR TIGER AlienVault 2025-03-10 Modified: 2025-03-10
53
IOCs
HIGH VOLUME
The SideWinder APT group intensified its activities in the second half of 2024, targeting maritime infrastructures, logistics companies, and nuclear sectors across Asia, the Middle East, and Africa. The group updated its toolset, including improvements to its RTF exploit, JavaScript loader, and Backdoor Loader. SideWinder's infection chain begins with spear-phishing emails containing malicious DOCX files, exploiting CVE-2017-11882 to deliver a multi-stage payload. The group demonstrated agility in evading detection, often updating their tools within hours of being identified. Notable targets included government entities, military installations, and diplomatic missions, with an increased focus on maritime and nuclear-related organizations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
StealerBot Downloader Module Module Installer
Indicators of Compromise (2 / 53 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 81d00923f2e9e0bae7c51ffbcb66409dd9a3da05 2025-03-10
FileHash-SHA1 dbc5756895b6585527bd6ebc4411ea6a4a6e2886 2025-03-10