SideWinder Threat Group's Updated Toolset Poses Risk to Maritime, Nuclear Sectors
Picus Security has identified updated tactics, techniques, and procedures (TTPs) used by the persistent SideWinder threat group. The group's refined toolset increasingly targets critical sectors, including maritime and nuclear facilities.

Picus Security has released an analysis detailing the evolving capabilities of the SideWinder threat group, a long-standing cyber-espionage actor active since at least 2012. The group has refined its tactics, techniques, and procedures (TTPs), expanding its targeting to include critical infrastructure sectors such as maritime and nuclear facilities.
According to the report, SideWinder has systematically broadened its geographic reach and sectoral focus over the years. Initially concentrating on regional intrusions, the group has since conducted wide-ranging campaigns across Asia, Africa, and parts of Europe. Recent activities indicate a heightened interest in government, military, financial, maritime, logistics, and nuclear-related entities.
The analysis highlights SideWinder's primary initial access vectors, which often involve highly tailored spearphishing emails containing malicious files or links. The group leverages Windows scripting environments for execution and maintains persistence through scheduled tasks and autostart mechanisms. Advanced defense evasion techniques, including obfuscation and masquerading, alongside robust credential theft capabilities, are also employed.
Notable past operations include a COVID-19-themed campaign in 2020 and expansive multi-country campaigns between 2021 and 2024 targeting over 60 entities. In 2024, SideWinder has reportedly expanded its operations into Africa and Europe, with a specific focus on maritime infrastructure and nuclear power facilities in South Asia.
Picus Security provides security solutions designed to help organizations detect and defend against advanced persistent threats like SideWinder. The firm's analysis aims to inform potential targets about the group's current operational methods and bolster defensive strategies.