Sidewinder, also tracked as TA399, is an India-aligned espionage threat actor. It is part of a broader cluster of India-nexus activity observed targeting individuals and organizations in South Asia and adjacent regions. The actor has been associated with phishing-led operations and has shown overlap with other India-aligned clusters in lure themes, use of compromised accounts, and victimology. Sidewinder has been observed sharing lure themes and compromised-account infrastructure patterns with TA395, also known as Frantic Tiger, and the two have at times targeted the same individuals. This overlap has led researchers to assess that some India-aligned clusters may benefit from shared resourcing or coordinated tasking, while still being tracked as distinct actors. Available reporting in this context supports classifying Sidewinder primarily as an espionage actor. The supplied facts do not directly establish a ransomware or extortion role for Sidewinder, nor do they provide high-confidence, actor-specific detail on malware families, intrusion chain specifics, or sector-by-sector targeting beyond its overlap with other India-aligned operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.