Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: T-APT-04, Rattlesnake
30
techniques
1
software
11,663
corpus matches
profile
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.
techniques
30 attributed · most-instrumented first
software
1 malware & tools attributed
Koadic
S0250
read this carefully
11,663 corpus matches is not attribution
That count is indicators which exhibit techniques Sidewinder is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
stealth
+18 more techniques
showing 30 of 11,663
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.