Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0112
MITRE ATT&CK Group

Windshift (G0112)

Bahamut
ShareXLinkedInRedditHN

[Windshift](https://attack.mitre.org/groups/G0112) is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.(Citation: SANS Windshift August 2018)(Citation: objective-see windtail1 dec 2018)(Citation: objective-see windtail2 jan 2019)

▪Techniques used (35)

T1057Process DiscoveryT1189Drive-by CompromiseT1059.005Visual BasicT1518.001Security Software DiscoveryT1566.001Spearphishing AttachmentT1204.001Malicious LinkT1566.003Spearphishing via ServiceT1547.001Registry Run Keys / Startup FolderT1518Software DiscoveryT1566.002Spearphishing LinkT1036.001Invalid Code SignatureT1027Obfuscated Files or InformationT1071.001Web ProtocolsT1036MasqueradingT1105Ingress Tool TransferT1047Windows Management InstrumentationT1033System Owner/User DiscoveryT1082System Information DiscoveryT1204.002Malicious FileT1636.003Contact ListT1633.001System ChecksT1628.003Conceal Multimedia FilesT1420File and Directory DiscoveryT1429Audio CaptureT1533Data from Local SystemT1512Video CaptureT1426System Information DiscoveryT1636.004SMS MessagesT1417.001KeyloggingT1632.001Code Signing Policy ModificationT1430Location TrackingT1406Obfuscated Files or InformationT1521.001Symmetric CryptographyT1627.001GeofencingT1407Download New Code at Runtime

▪Software used (1)

S0466WindTailmalware
G0112on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.