Thursday, April 30, 2026
  • About
  • Advertise
  • Careers
  • Contact
NewsTrendsKE
  • Business
    • Deals
  • OpEds
  • Sustainability
  • Women in Business
  • Lifestyle
  • Featured
  • Technology
    • Phones
  • Sports
  • World
  • Contact Us
No Result
View All Result
NewsTrendsKE
No Result
View All Result

Home » Featured » Kaspersky identifies SideWinder Advanced Persistent Threat (APT) expanding attacks with new espionage tool

Kaspersky identifies SideWinder Advanced Persistent Threat (APT) expanding attacks with new espionage tool

Editor by Editor
17 October 2024
in Featured, Technology
Reading Time: 3 mins read
A A
Share on FacebookShare on TwitterShare on WhatsApp

The Kaspersky Global Research and Analysis Team (GReAT) has detected that the SideWinder APT group is expanding its attack operations into the Middle East and Africa, utilising a previously unknown espionage toolkit called ‘StealerBot’. As part of its ongoing monitoring of APT activities, Kaspersky (www.Kaspersky.co.za) discovered that recent campaigns by the SideWinder APT group were targeting high-profile entities and strategic infrastructures in various countries in the Middle East, Turkiye, as well as in Morocco and Djibouti in Africa. The campaign in general remains active and may target other victims.

Also Read

Stanbic Bank Recognised at 2026 Think Business Awards

Stanbic Bank Scoops Four Honours at 2026 Think Business Awards

29 April 2026
HassConsult

Nairobi property market slows as rents and house prices rise – HassConsult Q1 2026 Report Shows

29 April 2026
Load More

SideWinder, also known as T-APT-04 or RattleSnake, is one of the most prolific APT groups that started operations in 2012. Over the years, it has primarily targeted military and government entities in Pakistan, Sri Lanka, China, and Nepal, as well as other sectors and countries in South and Southeast Asia. Recently, Kaspersky observed new waves of attacks, which have expanded to impact high-profile entities and strategic infrastructure in the Middle East and Africa.

Besides the geographical expansion, Kaspersky discovered that SideWinder is using a previously unknown post-exploitation toolkit called ‘StealerBot’. This is an advanced modular implant designed specifically for espionage activities, and currently used by the group as the main post-exploitation tool.

“In essence, StealerBot is a stealthy espionage tool that allows threat actors to spy on systems while avoiding easy detection. It operates through a modular structure, with each component designed to perform a specific function. Notably, these modules never appear as files on the system’s hard drive, making them difficult to trace. Instead, they are loaded directly into the memory. At the core of StealerBot is the ‘Orchestrator’, which oversees the entire operation, communicating with the threat actor’s command-and-control server, and coordinating the execution of its various modules”, says Giampaolo Dedola, lead security researcher at Kaspersky’s GReAT.

During its latest investigation, Kaspersky observed that StealerBot is performing a range of malicious activities, such as installing additional malware, capturing screenshots, logging keystrokes, stealing passwords from browsers, intercepting RDP (Remote Desktop Protocol) credentials, exfiltrating files, and more.

Kaspersky first reported on the group’s activities in 2018. This actor is known to rely on spear-phishing emails as its main infection method, containing malicious documents exploiting Office vulnerabilities and occasionally making use of LNK, HTML and HTA files that are contained in archives. The documents often contain information obtained from public websites, which is used to lure the victim into opening the file and believing it to be legitimate. Kaspersky observed several malware families being used within parallel campaigns, including both custom-made and modified, publicly available RATs.

To mitigate threats related to APT activities, Kaspersky experts recommend equipping your organisation’s information security experts with the latest insights and technical details, such as from Kaspersky Threat Intelligence Portal (https://apo-opa.co/4h4twjX); use robust solutions for endpoints and to detect advanced threats on the network, such as Kaspersky Next and Kaspersky Anti Targeted Attack Platform; educate employees to recognise cybersecurity threats such as phishing letters.

Read more on Securelist (https://apo-opa.co/4h5gQJA).

Distributed by APO Group on behalf of Kaspersky.

For further information please contact:
Nicole Allman
INK&Co. (https://INKAndCo.co.za/)
nicole@inkandco.co.za

Social Media:
Facebook: https://apo-opa.co/4f6ug6s
X (Twitter): https://apo-opa.co/3BY9AyU
YouTube: https://apo-opa.co/4foTBZx
Instagram: https://apo-opa.co/4f4zhMO
Blog: https://apo-opa.co/4h7jGha

About Kaspersky:
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.Kaspersky.co.za. 

Media files

Download logo
Previous Post

GITEX DIGI_HEALTH 5.0 Dubai showcases the future of Artificial Intelligence (AI)-driven innovations

Next Post

GITEX GLOBAL 2024: Artificial Intelligence (AI) revolution unveiled to the world on “AI Super Tuesday”

Related Posts

Stanbic Bank Recognised at 2026 Think Business Awards
Business

Stanbic Bank Scoops Four Honours at 2026 Think Business Awards

29 April 2026
HassConsult
National

Nairobi property market slows as rents and house prices rise – HassConsult Q1 2026 Report Shows

29 April 2026
Samsung Electronics
Technology

Two Decades of Samsung TVs Shaping the Modern Living Room Experience

28 April 2026
Signvrse
Technology

How the movie ‘Avatar’ inspired a Kenyan company Signvrse to develop tech for the deaf community

28 April 2026
Kieran Godden, Group CEO, Liberty Kenya Holdings Plc, and Anjali Harkoo, Head of Insurance and Asset Management at Stanbic Bank Kenya, during the signing of a Vehicle and Asset Financing partnership between Stanbic Bank and Liberty Kenya.

Stanbic Bank Kenya Designs Enhanced Insurance Cover for Commercial Vehicles Amid Rapid SME Sector Growth

28 April 2026
Stanbic Bank Recognised at 2026 Think Business Awards

Stanbic Bank Scoops Four Honours at 2026 Think Business Awards

29 April 2026
HassConsult

Nairobi property market slows as rents and house prices rise – HassConsult Q1 2026 Report Shows

29 April 2026
Mohit Claims Victory in the Opening Leg of the PGK Equator Golf Tour Second Edition

Mohit Claims Victory in the Opening Leg of the PGK Equator Golf Tour, Second Edition

27 April 2026
Cherie Kihato

Cherie Kihato is building African luxury one handcrafted piece at a time

20 April 2026
Zero Trace Phone

Zero Trace Phone: All you need to know about little known smartphone that leave no digital footprints

6 January 2025
NewsTrendsKE

NewsTrendsKE

A News Blog For Readers Who Want More

Follow us on social media:

  • About
  • Advertise
  • Careers
  • Contact

©2026 NewsTrendsKE.

error:
No Result
View All Result
  • Business
    • Deals
  • OpEds
  • Sustainability
  • Women in Business
  • Lifestyle
  • Featured
  • Technology
    • Phones
  • Sports
  • World
  • Contact Us

©2026 NewsTrendsKE.

Go to mobile version