Rewterz
Rewterz Threat Advisory – CVE-2021-39021 – IBM Security Guardium Data Encryption Vulnerability
February 4, 2022
Rewterz
Rewterz Threat Alert – Kimsuky APT Group – Active IOCs
February 4, 2022

Rewterz Threat Alert – APT SideWinder Group – Active IOCs

Severity

High

Analysis Summary

Sidewinder is a suspected Indian threat actor group that has been active since 2012. They have observed attacking political, military, and corporate organizations throughout Asia, with Pakistan, China, Nepal, and Afghanistan being the most common targets. RAZOR TIGER, Rattlesnake, APT-C-17, and T-APT-04 are some of the other names for Sidewinder APT. It has been detected targeting Pakistani government officials with a decoy file related to COVID-19 in its most recent effort. They employ custom implementations to attack existing vulnerabilities and then deploy a Powershell payload in the final stages to distribute the malware. Sidewinder was also detected employing credential phishing sites that were copied from their victims’ webmail login pages.

Impact

  • Information Theft and Espionage

Indicators of Compromise

Filename

  • FBR_Awareness_document[.]pdf[.]lnk

MD5

  • f77ff47ccf59cf1fe7f4dc8c31abbd64

SHA-256

  • 85ab1c3ee01c5456eb45bf13c69dda88fa014a1dc5e832bdaa3e801a29d84ccd

SHA-1

  • a762fbd8fea5b5bdcf0562caeaf85490b6868ff8

Remediation

  • Always be suspicious about emails sent by unknown senders.
  • Never click on links/attachments sent by unknown senders.
  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.