Group-IB reported renewed activity by APT SideWinder, describing a sustained cyber-espionage campaign aimed at government, military, and maritime organizations across Asia. The operation was characterized by targeted intrusion activity and a recognizable tradecraft pattern that researchers said allowed them to track the actor across multiple incidents.
The report said SideWinder continued to rely on spearphishing and malware delivery techniques tailored to regional targets, reinforcing the group’s role as a persistent intelligence threat rather than a financially motivated actor. Group-IB’s findings highlight SideWinder’s ongoing focus on sensitive institutions and critical sectors, with the campaign showing consistent operational behavior that supports attribution and threat hunting efforts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Group-IB published a blog post titled "The distinctive rattle of APT SideWinder," indicating public release of analysis related to the SideWinder threat actor. No additional incident dates or discrete events are provided in the reference content.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.