Netskope Threat Labs

Sidewinder

ATP Sandbox Adv. Heuristics

Sidewinder is an implant family associated with the Sidewinder threat actor, which researchers have also tracked as the Rattlesnake group. Its campaigns use South Asian territorial themes in spear phishing and have included mobile device attacks, with tooling that includes droppers and post exploitation frameworks such as Koadic and Meterpreter.

First seen
August 2023
Last seen
October 2026
SideWinder
Alert Name
ByteCode-MSIL.Trojan.Sidewinder
Document-RTF.Trojan.SideWinder
Document-Word.Trojan.Sidewinder
Script-JS.Trojan.Sidewinder
Script-Macro.Trojan.SideWinder
Win32.Trojan.Sidewinder
Win32.Trojan.SideWinder
Win64.Trojan.Sidewinder