Group-IB reported renewed activity by APT SideWinder, describing a sustained cyber-espionage campaign aimed at government, military, and maritime organizations across Asia. The operation was characterized by targeted intrusion activity and a recognizable tradecraft pattern that researchers said allowed them to track the actor across multiple incidents.
The report said SideWinder continued to rely on spearphishing and malware delivery techniques tailored to regional targets, reinforcing the group’s role as a persistent intelligence threat rather than a financially motivated actor. Group-IB’s findings highlight SideWinder’s ongoing focus on sensitive institutions and critical sectors, with the campaign showing consistent operational behavior that supports attribution and threat hunting efforts.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Group-IB published a blog post titled "The distinctive rattle of APT SideWinder," indicating public release of analysis related to the SideWinder threat actor. No additional incident dates or discrete events are provided in the reference content.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.