Threat Actor ๐ฎ๐ณ India
RAZOR TIGER
Also known as: SideWinder ยท Rattlesnake ยท APT-C-17 ยท T-APT-04
An actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian company. To spread the malware, they use unique implementations to leverage the exploits of known vulnerabilities (such as CVE-2017-11882) and later deploy a Powershell payload in the final stages.
Indicators of Compromise 11
MITRE ATT&CK TTPs 27
T1016 T1021.001 T1053.005 T1055 T1056.003 T1059.001 T1070.004 T1071.001 T1071.004 T1074.001 T1080 T1082 T1087.002 T1090.004 T1095 T1098.004 T1105 T1113 T1133 T1204.002 T1210 T1485 T1496 T1555 T1557.001 T1566 T1647
System Network Configuration Discovery
Discovery
Remote Desktop Protocol
Lateral Movement
Scheduled Task
Execution
Process Injection
Defense Evasion
Web Portal Capture
Collection
PowerShell
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
DNS
Command And Control
Local Data Staging
Collection
Taint Shared Content
Lateral Movement
System Information Discovery
Discovery
Domain Account
Discovery
Domain Fronting
Command And Control
Non-Application Layer Protocol
Command And Control
SSH Authorized Keys
Persistence
Ingress Tool Transfer
Command And Control
Screen Capture
Collection
External Remote Services
Persistence
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
Data Destruction
Impact
Resource Hijacking
Impact
Credentials from Password Stores
Credential Access
LLMNR/NBT-NS Poisoning and SMB Relay
Credential Access
Phishing
Initial Access
Plist File Modification
Defense Evasion
Source Articles
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Multiple active threat campaigns were reported, including a new SideWinder attack chain using ClickOnce files to deploy Rust-based backdoors, a large-scale npm supply chain attack named 'Flooding Dropper' involving 846 malicious packages, and a Chinese threat actor leveraging a DeepSeek AI agent in an LLM-managed campaign for proxyjacking. A new XCSSET macOS malware variant (v40) spreads via compromised Xcode projects and includes a Telegram trojanizer. The Gentlemen ransomware affiliate deployed EtherRAT, which retrieves C2 data from an Ethereum smart contract. Additionally, Interlock ransomware abused Volatility3 to extract credentials from memory, and a critical RCE flaw in the Odysseus AI workspace allowed authenticated users to execute OS commands. Several phishing campaigns used fake Bank of America and Coldcard wallet lures to install ScreenConnect, while AI-powered scam farms like FunFoneFarm lower the barrier to entry for cybercrime.
hacker-news ยท3w ago
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cyber espionage campaigns targeting Pakistani law enforcement agencies, including the Balochistan Police, have been conducted by suspected China- and India-aligned threat actors between February 2024 and April 2026. The attackers exploited web applications such as the Complaint Management System to deploy custom malware, including PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. These operations targeted sensitive data including biometric records, criminal files, and personnel information, with infrastructure overlaps linking some activity to known threat groups like Mysterious Elephant. The compromise of public-facing portals extended the attack surface to both law enforcement and citizens.
hacker-news ยท1mo ago