Researchers say the Sidewinder offensive cyber crew is starting to target maritime and nuclear organizations. Kaspersky described Sidewinder as a "highly prolific" advanced persistent threat (APT) group whose previous prey were mostly government and military instituions in China, Pakistan, Sri Lanka, and parts of Africa. Its recent wider expansion into Africa has caught researchers' attention. Sidewinder ramped up attacks in Djibouti in 2024 and has since focused its attention on Egypt, representing a shift in tactics. Part of that shift is the increase in attacks against nuclear power plants and other nuclear energy organizations, particularly in South Asia. Sidewinder, which launched in 2012 and has suspected but not formally confirmed roots in India, hasn't changed its attack methodology much, still relying on old remote code execution (RCE) bugs that are exploited by malicious documents delivered in spear-phishing campaigns. "The attacker sends spear-phishing emails with a DOCX file attached," said Kaspersky researchers Giampolo Dedola and Vasily Berdinkov. "The document uses the remote template injection technique to download an RTF file stored on a remote server controlled by the attacker. "The file exploits a known vulnerability (CVE-2017-11882) to run a malicious shellcode and initiate a multi-level infection process that leads to the installation of malware we have named Backdoor Loader. This acts as a loader for StealerBot, a private post-exploitation toolkit used e...
Sidewinder goes nuclear, charts course for maritime mayhem in tactics shift
The Register
·Connor Jones
·Published Mar 10, 2025
·Updated
Affected Software
1 affected component
Microsoft Office=2017
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the Sidewinder advanced persistent threat group shifting its focus to target maritime and nuclear organizations.
2
What security implications are discussed in the article?
The article highlights the potential risks to critical infrastructure in the maritime and nuclear sectors due to Sidewinder's new targeting strategies.
3
What products or software are affected by Sidewinder's tactics?
The article mentions Microsoft Office 2017 as potentially affected by the Sidewinder group's cyber operations.
4
Who is tracking the activities of the Sidewinder group?
Kaspersky is monitoring and providing insights on the activities and tactics of the Sidewinder APT group.
5
What characterization is given to the Sidewinder group by Kaspersky?
Kaspersky describes Sidewinder as a "highly prolific" cyber threat actor, indicating its significant capabilities and impact.