SideTwist is a Windows backdoor associated with the Iranian threat actor OilRig, also tracked as APT34 and linked in some reporting to Lyceum-related activity. It has been used in targeted espionage operations in the Middle East, including campaigns against enterprise and regional government-linked entities. Delivery has been observed through phishing documents with malicious macros that drop a SideTwist variant and establish persistence via scheduled tasks for repeated execution.
SideTwist is designed to provide long-term remote access to compromised hosts. Documented variants collect basic host-identifying information including username, computer name, and domain name, derive a victim identifier from that data, and communicate it to command-and-control infrastructure. The malware supports command execution as well as file upload and download, enabling both remote tasking and data theft. Exfiltration has been observed over the same command-and-control channel used for operator communications.
Its network communications are obfuscated and encrypted. Reported variants have used Base64 encoding for command-and-control traffic and can encrypt communications with a randomly generated key; they also decode and decrypt instructions received from the server. SideTwist has primarily communicated over port 443 with port 80 available as a fallback, and some variants have parsed commands embedded in HTML content returned by the server. Operationally, certain samples execute a single command-and-control session and rely on scheduled-task persistence to re-establish contact periodically.
Observed tradecraft indicates a focus on stealth and resilience rather than broad self-propagation. Variants have included execution checks consistent with anti-analysis behavior and have been deployed in phishing campaigns using business-themed or administrative lures. SideTwist remains best characterized as an espionage-oriented Windows backdoor used for persistent access, host profiling, remote command execution, and file transfer in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In April 2021, the actor targeted a Lebanese entity with an implant called SideTwist...
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious macro then creates a scheduled task called SystemFailureReporter that calls up the Trojan every 5 minutes, through which it runs repeatedly.
Several entries refer generically to command-line interfaces, shell commands, scripting engines, or script execution without always specifying the exact interpreter.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
BoxCaon has used Windows API calls to obtain information about the compromised host.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor malware previously associated with APT34. In this content it is used as the comparison point for Menorah, with noted similarities in victim fingerprinting, C2 communication, shell command execution, and file upload/download capabilities.
APT34-used trojan/backdoor variant that establishes persistence via a scheduled task, checks for an update.xml file as an anti-sandbox gate, collects host identifiers, communicates with a C2 over HTTP, executes shell commands, downloads files, uploads local files, and then exits until reinvoked.
Backdoor that can collect the username on a targeted system.
Collects domain names from compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.