Cyber Resilience

Threat actor · all actors

SidewinderG0121 state

🇮🇳 IN

aka Sidewinder, T-APT-04, Rattlesnake, RAZOR TIGER, APT-C-17

Last updated: 2026-08-20

1attributed CVEs
42ATT&CK techniques
4.3IDF score (tooling uniqueness)
1exclusive CVEs
2018years active

About this actor

[Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.(Citation: ATT Sidewinder January 2021)(Citation: Securelist APT Trends April 2018)(Citation: Cyble Sidewinder September 2020)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0121

CrowdStrikenation-animal names

RAZOR TIGER

Unclassifiedno scheme matched

SidewinderT-APT-04RattlesnakeAPT-C-17

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 42 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2018-4876 5.26.10.04602018-02-27see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-328 / 4267%
SI-428 / 4267%
CM-627 / 4264%
CM-226 / 4262%
CA-720 / 4248%
CM-718 / 4243%
AC-417 / 4240%
SC-716 / 4238%
SI-715 / 4236%
SI-1013 / 4231%
SI-213 / 4231%
AC-611 / 4226%
CM-811 / 4226%
RA-511 / 4226%
AC-310 / 4224%

Co-occurring actors

None.

Similar actors

Similar TTPs

Active in same years