Netskope Threat Labs

SideTwist

ATP Sandbox Adv. Heuristics

SideTwist is a C based backdoor that the OilRig threat actor has used since at least 2021.

First seen
April 2022
Last seen
October 2026
Sidetwist

15 techniques across 6 tactics.

TA0002 Execution

TA0005 Stealth

  • T1140Deobfuscate/Decode Files or Information

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
ByteCode-MSIL.Trojan.Sidetwist
Document-Word.Dropper.SideTwist
Document-Word.Trojan.Sidetwist
Win32.Backdoor.Sidetwist