Rewterz
Rewterz Threat Alert – Amadey Botnet – Active IOCs
December 23, 2022
Rewterz
Rewterz Threat Alert – Panda Stealer Malware – Active IOCs
December 23, 2022

Rewterz Threat Alert – APT SideWinder Group Targeting Pakistan – Active IOCs

Severity

High

Analysis Summary

Sidewinder is a suspected Indian threat actor group that has been active since 2012. They have observed attacking political, military, and corporate organizations throughout Asia, with Pakistan, China, Nepal, and Afghanistan being the most common targets. RAZOR TIGER, Rattlesnake, APT-C-17, and T-APT-04 are some of the other names for Sidewinder APT. It has been detected targeting Pakistani government officials with a decoy file related to COVID-19 in its most recent effort. They employ custom implementations to attack existing vulnerabilities and then deploy a Powershell payload in the final stages to distribute the malware. Sidewinder was also detected employing credential phishing sites that were copied from their victims’ webmail login pages.

Impact

  • Information Theft and Espionage

Indicators of Compromise

MD5

  • 6484a83a2c7ac173cad630d871ba8f63

SHA-256

  • a2faee1e5fe8717d6360458f1fd6d83902a2c9c6bb2e84f9ea5e4b67ffafbebd

SHA-1

  • fcd7a0ac708347a3ea2089bdf150fb9b095c5e81

Domain Name

  • mailmofa.alit.info
  • maildefence.alit.info
  • foodies.alit.info
  • mail.alit.info
  • alit.info

Remediation

  • Block all threat indicators at your respective controls.
  • Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls
  • Emails from unknown senders should always be treated with caution.
  • Never trust or open ” links and attachments received from unknown sources/senders.