Sidewinder has used malware to collect information on network interfaces, including the MAC address.4
group
Sidewinder G0121
- Created
- 27 January 2021
- Last modified
- 31 July 2026
- Aliases
- Sidewinder · T-APT-04 · Rattlesnake
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0121
Sidewinder has configured tools to automatically send collected files to attacker controlled servers.5
Sidewinder has used base64 encoding for scripts.67
Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.8910
Sidewinder has used tools to identify the user of a compromised host.11
Sidewinder has named malicious files rekeywiz.exe to match the name of a legitimate Windows executable.12
Standing G0121
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
66th percentile · 66% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
59th percentile · 59% of 176 ATT&CK groups have this many tactics spanned or fewer.
23rd percentile · 77% of 176 ATT&CK groups have more tools and malware.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
58th percentile · 58% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0121
1055 distinct rules cover the 30 techniques recorded for this group. The 1175 technique-to-rule mappings resolve to 1055 distinct rules, because one rule can cover several techniques. 770 Sigma · 285 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org