s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.sidewinder

📛 Threat Title

Malware family: SideWinder

Category: SideWinder First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.sidewinder`. Printable name: SideWinder.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.sidewinder VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.sidewinder

IOC database

Type
domain
Value
apk.sidewinder
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.sidewinder

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.sidewinder

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The comprehensive set of techniques and functions within the malware , combined with its modularity and adaptability, illustrate the evolving landscape of cyber-espionage and the critical need for advanced threat intelligence and mitigation strategies in defending against such intricate campaigns.

  • web:attack.mitre.org

    Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.

  • web:cyberpress.org

    The long-lived campaign showcases SideWinder's operational continuity and refinement: despite relying on patched vulnerabilities disclosed in 2017, many organizations remain vulnerable due to outdated software deployments and insufficient patch management. SideWinder's infrastructure exhibited bursts of domain registrations and repointing in early 2025, indicating phases of active ...

  • web:cybersecurityasia.net

    The malware is designed to extract login credentials from compromised systems, enabling prolonged and stealthy access. These techniques mark an evolution in SideWinder's toolkit, aligning with its past activity but revealing refinements in execution and targeting strategy.

  • web:cybersecuritynews.com

    Cybersecurity researchers have identified intensified activity from the SideWinder APT group throughout 2024, with significant updates to their toolset and expanded targeting beyond traditional military and government entities. Recent findings reveal that SideWinder has developed a massive new infrastructure to distribute malware and control compromised systems, with a notable increase in ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the SideWinder malware family including references, samples and yara signatures.

  • web:thehackernews.com

    SideWinder APT expands attacks on maritime, nuclear, and IT sectors, rapidly modifying malware to evade detection.

  • web:windowsforum.com

    The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .

  • web:www.broadcom.com

    A new cyber-espionage campaign by APT group SideWinder has been targeting high-profile government institutions in Bangladesh, Pakistan, and Sri Lanka. The attackers leverage spear-phishing lures paired with geofenced payloads to ensure that only victims in specific countries receives the malicious content. To activate the infection process and deploy the StealerBot malware a combined ...

  • web:www.cyberstash.com

    The targeting of maritime and nuclear infrastructure—combined with post-compromise activity that includes tailored malware deployment and advanced evasion tactics—suggests an intelli-gence-driven campaign with strategic geopolitical objectives. The group's ability to retool within hours of detection, coupled with its use of complex infection chains and memory-resident pay-loads, reflects ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.