Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0121
MITRE ATT&CK Group

Sidewinder (G0121)

T-APT-04Rattlesnake
ShareXLinkedInRedditHN

[Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.(Citation: ATT Sidewinder January 2021)(Citation: Securelist APT Trends April 2018)(Citation: Cyble Sidewinder September 2020)

▪Techniques used (30)

T1203Exploitation for Client ExecutionT1518.001Security Software DiscoveryT1218.005MshtaT1598.003Spearphishing LinkT1124System Time DiscoveryT1566.002Spearphishing LinkT1074.001Local Data StagingT1057Process DiscoveryT1059.007JavaScriptT1027.013Encrypted/Encoded FileT1020Automated ExfiltrationT1105Ingress Tool TransferT1547.001Registry Run Keys / Startup FolderT1071.001Web ProtocolsT1559.002Dynamic Data ExchangeT1083File and Directory DiscoveryT1016System Network Configuration DiscoveryT1598.002Spearphishing AttachmentT1027.010Command ObfuscationT1059.001PowerShellT1518Software DiscoveryT1059.005Visual BasicT1082System Information DiscoveryT1119Automated CollectionT1566.001Spearphishing AttachmentT1036.005Match Legitimate Resource Name or LocationT1204.001Malicious LinkT1204.002Malicious FileT1033System Owner/User DiscoveryT1574.001DLL

▪Software used (1)

S0250Koadictool
G0121on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.