Microsoft Word - Global Perspective of the SideWinder APT (pre-release final).docx
ID: e08d514e-fb47-4044-9785-75020c959442
STIX ID: report--e08d514e-fb47-4044-9785-75020c959442
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2021-01-11
Last Modified Date: 2021-01-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AT&T Alien Labs presents a comprehensive analysis of the SideWinder APT, detailing multi-year targeted campaigns across South and East Asia that use spearphishing, weaponized RTF (CVE-2017-11882), HTA downloaders, DLL side‑loading and in‑memory implants to collect and exfiltrate files and system information; the report includes ATT&CK mappings, detection signatures (YARA, Suricata), and an extensive appendix of domains, hostnames and file hashes as IOCs for retrospective detection and remediation.
