SideWinder, Rattlesnake - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:21:23 UTC Home > List all groups > SideWinder, Rattlesnake APT group: SideWinder, Rattlesnake Names SideWinder (Kaspersky) Rattlesnake (Tencent) Razor Tiger (CrowdStrike) T-APT-04 (Tencent) APT-C-17 (Qihoo 360) Hardcore Nationalist (?) HN2 (?) APT-Q-39 (?) BabyElephant (?) GroupA21 (?) G0121 (MITRE) Country India Motivation Information theft and espionage First seen 2012 Description (Kaspersky) An actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence t malware might be authored by an Indian company. To spread the malware, they use unique implementations to lever exploits of known vulnerabilities (such as CVE-2017-11882) and later deploy a Powershell payload in the final stage Observed Sectors: Defense, Government, Maritime and Shipbuilding. Countries: Afghanistan, Bangladesh, Bhutan, Cambodia, China, Djibouti, Egypt, Maldives, Myanmar, Nepal, Pakista Lanka, Turkey, UAE, Vietnam. Tools used BroStealer, callCam, Capriccio RAT. Operations performed Mar 2019 First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Jun 2021 Old Snake, New Skin: Analysis of SideWinder APT activity between June and November 2021 Mar 2022 SideWinder’s malicious document, which also exploit the Russia-Ukraine conflict, was uploaded to middle of March. May 2022 Group-IB Threat Intelligence researchers have discovered a new malicious infrastructure and a cust the APT group SideWinder Nov 2022 SideWinder Uses Server-side Polymorphism to Attack Pakistan Government Officials — and Is Now Turkey sea> 2024 SideWinder targets the maritime and nuclear sectors with an updated toolset Information MITRE ATT&CK Last change to this card: 16 August 2025 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=5d4ae207-898e-4cb8-9d60-8bfa060abf42 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=5d4ae207-898e-4cb8-9d60-8bfa060abf42 Page 2 of 2