Full Report
Bridewell and Group-IB expose the APT’s unknown infrastructure
Analysis Summary
# Threat Actor: SideWinder
## Attribution & Identity
* **Actor Name:** SideWinder
* **Aliases:** APT-C-17, T-APT-04, Rattlesnake, Razor Tiger
* **Known Associations:** Believed to be an Indian-state-sponsored group, active since at least 2012.
## Activity Summary
Based on the collaboration between Bridewell and Group-IB, recent operations involve the expansion of a massive, previously unknown infrastructure. The actor continues to focus on espionage through the use of highly targeted spear-phishing and the deployment of custom malware. The report highlights the discovery of dozens of new Command and Control (C2) nodes and domains used to facilitate data exfiltration and persistent access.
## Tactics, Techniques & Procedures
SideWinder is known for high-volume operations and repetitive use of successful techniques:
* **Spear-phishing:** Delivery of malicious attachments (LNK files, Office documents with remote template injection).
* **DLL Side-Loading:** Used to execute malicious payloads while evading security software.
* **JavaScript Obfuscation:** Heavy use of obfuscated scripts in the initial infection chain.
* **Infrastructure Mimicry:** Registering domains that spoof legitimate government and military portals to deceive targets.
**MITRE ATT&CK IDs:**
* **T1566:** Phishing
* **T1059:** Command and Scripting Interpreter
* **T1574.002:** DLL Side-Loading
* **T1071.001:** Web Protocols (Application Layer Protocol)
## Targeting
* **Sectors:** Government, Military, Defense Industry, Foreign Affairs, and Law Enforcement.
* **Geography:** Primarily South Asia and Southeast Asia (Pakistan, China, Nepal, Afghanistan, Bangladesh, and Sri Lanka).
* **Victims:** Specifically mentions spoofed entities related to Pakistan (PTCL, NTC, CSD Store) and educational/government sectors (FIA, government mail portals).
## Tools & Infrastructure
* **Malware:** SideWinder custom backdoors (often RATs based on .NET), information stealers.
* **Infrastructure (Defanged):**
* **IPs:**
* 149.154.154[.]65
* 151.236.14[.]56
* 151.236.21[.]70
* 185.174.135[.]31
* 5.230.73[.]180
* 5.255.112[.]178
* **Domains:**
* storeapp[.]site
* ridlay[.]live
* ptcl-gov[.]org
* ntc-pk[.]com
* pak-gov[.]info
* csdstore[.]app
* govpk-mail[.]org
* fia-gov[.]com
## Implications
SideWinder remains one of the most prolific APT actors in terms of the sheer number of campaigns launched. The discovery of such vast infrastructure suggests the actor is not only maintaining its current operational tempo but scaling up for broader regional espionage. Their ability to consistently reuse WHOIS data (e.g., "13th street auckland") indicates a calculated balance between speed of deployment and operational security.
## Mitigations
* **Network Monitoring:** Monitor for connections to the identified IP ranges and domains, particularly those mimicking government infrastructure.
* **Email Security:** Implement robust attachment filtering for LNK, HTA, and macro-enabled Office documents.
* **Endpoint Protection:** Deploy EDR solutions to detect DLL side-loading and unusual JavaScript execution (wscript/cscript) originating from temp folders.
* **Threat Hunting:** Use Shodan and similar tools to identify infrastructure patterns (certificates, WHOIS data) associated with SideWinder’s known clusters.