Alpha Cyber

Mapping the Invisible Enemy: Sidewinder (APT-04) Indian-Linked Cyber Threat Infrastructure

In the modern threat landscape, advanced persistent threats (APTs) operate like invisible war machines, strategic, highly coordinated, and capable of maintaining long-term access to their targets.

Alpha Cyber Research1 min readupdated 1 Apr 2026
Sidewinder Malware Infra Graph

Mapping Sidewinder (APT-04) Indian-Linked Cyber Threat Infrastructure

In the modern threat landscape, advanced persistent threats (APTs) operate like invisible war machines, strategic, highly coordinated, and capable of maintaining long-term access to their targets. One of the most persistent and regionally aggressive APTs is Sidewinder (APT‑04), widely attributed to state-linked actors operating from India.

Known for targeting government, military, energy, and telecom sectors, particularly across South and Southeast Asia, Sidewinder leverages a complex and layered infrastructure to execute its campaigns. Their operations rely heavily on modular malware loaders, overlapping C2 domains, and phishing infrastructure designed to impersonate government or military entities.

Understanding the Sidewinder Infrastructure

Sidewinder’s digital footprint is highly dynamic and deliberately obfuscated. Over the past few years, the group has evolved its malware delivery systems using techniques such as:

  • Rotating domain names and IPs hosted on bulletproof VPS providers
  • Hosting payloads behind decoy government-themed URLs
  • Using weaponized Microsoft Office documents exploiting known CVEs
  • Layered Command-and-Control (C2) servers, often operating through CDN fronting or subdomain hijacking

This infrastructure allows Sidewinder to shift attack vectors quickly, evade detection, and maintain persistent surveillance on high-value targets.

Indicators of Compromise (IOCs) – Block Immediately

IOC Type Value / Description
Filenames CRC.docx, Briefing on Ongoing Projects.docx (decoy documents used during phishing)
File Hashes e9726519487ba9e4e5589a8a5ec2f933
 d36a67468d01c4cb789cd6794fb8bc70
 313f9bbe6dac3edc09fe9ac081950673
Additional DOCX  hashes  a694ccdb82b061c26c35f612d68ed1c2
 f42ba43f7328cbc9ce85b2482809ff1c
Malicious Domains Numerous fake domains used for payload download, e.g. modpak‑info.services, pmd‑office.info 
C2 Infrastructure URLs hosting final-stage payloads: e.g., mailmofagovmm.mofa.email/hybridwarfare-866394/file.rtf 

Blocking these indicators at your firewall, endpoint, and DNS layers can significantly reduce risk exposure.

Ready to See Their Map?

Need visibility into APT infrastructure? Let Alpha Cyber  help you map, monitor, and mitigate threats like Sidewinder, before they strike.
Reach out to our team today for expert guidance and a tailored threat intelligence demo.
Gain access to the Sidewinder/APT-04 infrastructure map, and learn how to integrate it into your defense strategy today.

Stop guessing. Start mapping. Outsmart APTs.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]