SideWinder’s Growing Focus on Maritime and Nuclear Entities

Red | Attack Report
Download PDF

SideWinder, a persistent APT group, continues targeting government, military, maritime, and nuclear sectors across Asia, the Middle East, and Africa. Their attack chain begins with spear-phishing emails exploiting CVE-2017-11882 to deploy StealerBot, enabling espionage via credential theft, keylogging, and file exfiltration. The group rapidly evolves its malware to evade detection, often modifying tools within hours. Strong security measures, including patch management and phishing awareness, are crucial to countering this threat.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox