Alpha Cyber

Unmasking SideWinder: LNK Phishing Attack Mapping for Enhanced Protection

The APT-C-24 (also known as SideWinder) hacker group has been actively employing LNK file phishing techniques in their recent attacks, posing significant risks to organizations worldwide.

Alpha Cyber Research2 min readupdated 1 Apr 2026
sidewinder APT

The APT-C-24 (also known as SideWinder) hacker group has been actively employing LNK file phishing techniques in their recent attacks, posing significant risks to organizations worldwide. By exploiting malicious LNK files to drop malware and steal sensitive information, this group continues to evolve its tactics, making it crucial for businesses to stay one step ahead.

In this post, we break down the recent LNK file phishing attacks from APT-C-24 and provide an infrastructure map of their activities. Additionally, we present a comprehensive IOC table to help you block malicious indicators and safeguard your network.

Mapping the APT-C-24 Infrastructure

APT-C-24 (Sidewinder) Recent LNK File Phishing Attacks Hash Graph

APT-C-24 is known for using a combination of social engineering and malicious file execution to gain initial access. One of their latest techniques involves the use of LNK files, Windows shortcut files that execute malicious scripts or commands when opened. These files often look innocuous but are crafted to exploit vulnerabilities and drop payloads like SLF:Win32/LnkFileWithMshta.A, a type of Windows shortcut that leverages MSHTA for remote code execution.

By mapping the infrastructure tied to these attacks, businesses can now proactively identify and block suspicious files and domains tied to these operations.

IOC Table: Critical Indicators to Block

To help you defend against these targeted phishing campaigns, we’ve compiled a list of Indicators of Compromise (IOCs) directly tied to the latest SideWinder LNK file phishing attacks. Blocking these IOCs is a crucial step in securing your network against this threat.

Indicator TypeIOCDescription
FileHash-MD51912b2d5e88d8dc277c7890bb4a318e0Malicious LNK file used in phishing attack.
FileHash-MD5193a676eb9f32a8106ac4282eca90385SLF:Win32/LnkFileWithMshta.A – Phishing vector.
FileHash-MD52e382c82d055e6e3a5feb9095d759735Suspicious LNK file found in targeted email.
FileHash-MD53a97695937d9501423f100d76af24cc1LNK file associated with recent APT-C-24 attacks.
FileHash-MD53c92342e979a1b69abb3b2031c2dfa26SLF:Win32/LnkFileWithMshta.A – Executes malicious code.
FileHash-MD55ce07c6ce99724105168272cc4e90a30LNK file used in spear-phishing campaigns.
FileHash-MD55dd45b3cdf793c9f2d74209f58e555d6Another malicious LNK file deployed in attack chain.
FileHash-MD565c7b3577358f1d3ce4a004d4f73f35dLinked to APT-C-24 operations targeting govt orgs.
FileHash-MD56a36e86888e7f935f10fba64bd3bca0fLNK file part of lateral movement mechanism.
FileHash-MD56ad920494159cc05939306eaf4e0e24aAssociated with payload dropper for APT-C-24.
FileHash-MD56b0d026c57528db28cb9673248041e4aUsed in initial exploitation of user systems.
FileHash-MD56ff8bdc2193284cb386aef100a7ab1acAPT-C-24 backdoor LNK file.
FileHash-MD573a0170ea882989f6ffc3b4726a3ee56LNK file triggering payload execution.

How to Protect Your Organization

To stay secure, it’s essential to:

1. Monitor for LNK files in inbound emails and external downloads.
2. Block known IOCs like the MD5 hashes listed above using your firewall, endpoint protection, or IDS/IPS systems.
3. Use sandboxing and email filtering solutions to screen for malicious payloads.
4. Conduct regular employee training on recognizing phishing emails and handling suspicious attachments.
5. Apply timely patches to close vulnerabilities exploited by malicious LNK files.

By adopting these proactive security measures, you can minimize the risk of a breach due to APT-C-24’s LNK phishing tactics.

Conclusion

APT-C-24’s recent LNK file phishing attacks demonstrate the sophistication and persistence of modern cyber threats. With their ability to craft seemingly benign files that lead to devastating attacks, businesses must be vigilant and prepared.

By leveraging IOC mapping and blocking critical indicators associated with this threat group, you can safeguard your organization against SideWinder’s evolving tactics. Stay protected, stay ahead.

Let us help you defend your business. For more information or assistance, feel free to contact us and learn how our advanced cybersecurity services can mitigate risks posed by APT-C-24 and similar threats.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]