Threat actor · all actors
SidewinderG0121 state
🇮🇳 IN
aka Sidewinder, T-APT-04, Rattlesnake, RAZOR TIGER, APT-C-17
Last updated: 2026-08-20
About this actor
[Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.(Citation: ATT Sidewinder January 2021)(Citation: Securelist APT Trends April 2018)(Citation: Cyble Sidewinder September 2020)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 42 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2018 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2018-4876 | 5.2 | 6.1 | 0.0460 | 2018-02-27 | see CVE |
T1016System Network Configuration Discovery ↗T1020Automated Exfiltration ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1027.013Encrypted/Encoded File ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.005Visual Basic ↗T1059.007JavaScript ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1105Ingress Tool Transfer ↗T1119Automated Collection ↗T1124System Time Discovery ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.005Mshta ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1559Inter-Process Communication ↗T1559.002Dynamic Data Exchange ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1598Phishing for Information ↗T1598.002Spearphishing Attachment ↗T1598.003Spearphishing Link ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-3 | 28 / 42 | 67% |
SI-4 | 28 / 42 | 67% |
CM-6 | 27 / 42 | 64% |
CM-2 | 26 / 42 | 62% |
CA-7 | 20 / 42 | 48% |
CM-7 | 18 / 42 | 43% |
AC-4 | 17 / 42 | 40% |
SC-7 | 16 / 42 | 38% |
SI-7 | 15 / 42 | 36% |
SI-10 | 13 / 42 | 31% |
SI-2 | 13 / 42 | 31% |
AC-6 | 11 / 42 | 26% |
CM-8 | 11 / 42 | 26% |
RA-5 | 11 / 42 | 26% |
AC-3 | 10 / 42 | 24% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Windshift 0.43
- Patchwork 0.42
- SideCopy 0.40
- Frankenstein 0.37
- Confucius 0.37
Active in same years
- ArcaneDoor 1.00
- Lazarus Group 1.00
- Andariel 1.00
- Storm-0530 1.00
- Maui ransomware 1.00
Same nation-state
- C0011 1.00
- Tata Consultancy Services (Epic Systems case) 1.00
- Patchwork 1.00
- BITTER 1.00
- Indian Cyber Force 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00