Alpha Cyber

From Rootkits to Ransomware: Decoding SideWinder’s Newest Indian Campaign

Tax season is stressful enough without an Advanced Persistent Threat (APT) group living in your network.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Sidewinder APT Photo

SideWinder APT’s Multi-Vector Assault on Indian Taxpayers

Tax season is stressful enough without an Advanced Persistent Threat (APT) group living in your network.

Our latest intelligence has uncovered a massive expansion in the operations of SideWinder (also known as APT-C-17). Their newest play? A highly targeted campaign impersonating India’s Income Tax Department. This isn’t your run-of-the-mill phishing scam; it is a sophisticated offensive designed to bypass traditional defenses by hiding in plain sight.

1. The Multi-Vector Trap: Beyond the Windows Desktop

What makes this campaign particularly dangerous is its breadth. SideWinder isn’t just looking for a quick credit card number; they are seeking total persistence. Through our analysis of their current infrastructure, we’ve identified a sprawling web of malicious assets.

Virustotal Sidewinder surl.li Tax Impersonation  Caption: Analysis showing the rootkit.exe payload linked to initial access vectors.

  • The Desktop Payload: We’ve detected the deployment of the Tedy Rootkit via malicious links (often involving the surl.li shortener). Once a rootkit like rootkit.exe is on a Windows machine, it can hide files and processes from the operating system itself, making it nearly invisible to basic security tools.

Virustotal Sidewinder surl.li Tax Impersonation Rootkit Tedy

  • The Mobile Angle: They aren’t ignoring the mobile workforce. We identified a malicious Android package, TeleVibe.apk, which acts as a beachhead for data exfiltration directly from mobile devices.

  Caption: Mapping the connection between mobile APKs and malicious command-and-control infrastructure.

2. Hiding in the “Normal” Traffic

One of SideWinder’s most clever tactics is the use of “Living off the Land” techniques. They are leveraging legitimate time-synchronization APIs to mask their communications.

  • API Exploitation: By beaconing out to services like worldtimeapi.org and timeapi.io, the malware blends in with standard system traffic.

VirusTotal SideWinder Impersonation Graph timeapi.io televibe

  • The “Time” Trick: To a basic firewall, it looks like a computer just checking the time. To our analysts, it’s a clear signal of a compromised host synchronizing its attack window.

VirusTotal SideWinder Impersonation Graph worldtimeapi.org graph 

Caption: Technical visualization of how malware leverages legitimate APIs to bypass detection.

In a surprising twist, we’ve tracked connections to Mirai-linked infrastructure. This suggests SideWinder may be co-opting IoT devices to build a secondary layer of proxy infrastructure to further mask their origin. Furthermore, some payloads have been flagged by engines as having ransomware or file-coding characteristics, indicating the end goal may be more destructive than simple espionage.

Virustotal Sidewinder surl.li Tax Impersonation Mirai  

Caption: Evidence of Mirai-based botnet components integrated into the SideWinder campaign.

4. Why Your Perimeter is Failing

If you are relying on signature-based detection, you are already behind. Our tracking of the gfmqvip.vip domain a core piece of their current infrastructure showed that even while it was actively serving malware, many standard security engines were slow to flag it, with only 12 out of 93 engines identifying it initially

VirusTotal SideWinder Impersonation Graph  

 Caption: The “Lag Time” in detection how malicious domains stay active while security engines catch up.

The Alpha Cyber Advantage

At Alpha Cyber, we don’t wait for a vendor to release a patch. We map the adversary’s footprint before they even send the first email. We see the connections between a “Tax Department” PDF and a backend rootkit server in real-time.

Our services go beyond simple alerts; we provide the visibility required to stop an APT from turning a single click into a total breach.

Is your organization a target? The “Taxman” is already knocking on doors. Don’t wait until the audit results in a data breach.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]