The SideWinder espionage group, also tracked as RagaSerpent and suspected to be India-linked, has expanded targeted operations across Southeast Asia, including Thailand and Indonesia, with victims spanning government, telecommunications, critical infrastructure, maritime, logistics, and nuclear-sector organizations. Reporting indicates the campaign remains focused on intelligence collection and long-term access rather than disruption, with operators using spear-phishing, stolen credentials, older Microsoft Office vulnerabilities, and DLL hijacking to gain entry into victim environments.
Researchers said the group offsets these relatively simple intrusion methods with disciplined post-compromise tradecraft, including staged payload delivery, persistence through Windows services, and rapidly rotating command-and-control infrastructure. A notable feature of recent activity is malware that derives its C2 configuration dynamically at runtime, allowing operators to shift infrastructure without rebuilding payloads and complicating remediation. Separate reporting also links RagaSerpent to a multi-country targeted intrusion chain described as a SideWinder-adjacent "Tax Audit" cluster, reinforcing concerns that the threat actor is sustaining broad regional espionage activity and pre-positioning inside networks for strategic access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Recent reporting says the SideWinder espionage group expanded operations across Southeast Asia, including Thailand and Indonesia, targeting governments, telecommunications, critical infrastructure, maritime organizations, logistics firms, and the nuclear sector. Researchers described simple initial access methods paired with disciplined post-compromise tradecraft, staged payloads, service-based persistence, rotating C2 infrastructure, and runtime-derived C2 configuration.
A headline references a SideWinder-adjacent cluster called RagaSerpent conducting a multi-country targeted intrusion chain spanning 2025 to 2026. No further operational or victim details are provided in the source content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.