• Home
  • Agric
  • Sci & Tech
  • Health
  • Environment
  • Hausa News
  • More
    • Business/Banking & Finance
    • Politics/Elections
    • Entertainments & Sports
    • International
    • Investigation
    • Law & Human Rights
    • Africa
    • ACCOUNTABILITY/CORRUPTION
    • Hassan Gimba
    • Column
    • Prof. Jibrin Ibrahim
    • Prof. M.K. Othman
    • Defense/Security
    • Education
    • Energy/Electricity
    • Entertainment/Arts & Sports
    • Society and Lifestyle
    • Food & Agriculture
    • Health & Healthy Living
    • International News
    • Interviews
    • Investigation/Fact-Check
    • Judiciary/Legislature/Law & Human Rights
    • Oil & Gas/Mineral Resources
    • Press Freedom/Media/PR/Journalism
    • General News
    • Presidency
  • About Us
    • Contact Us
    • Board Of Advisory
    • Privacy Policy
    • Ethics Policy
    • Teamwork And Collaboration Policy
    • Fact-Checking Policy
    • Advertising
  • Media OutReach Newswire
    • Wire News
  • The Stories
Facebook Twitter Instagram
Trending
  • Nigerian freelancers face rising financial pressure
  • Airtime borrowing myths debunked by FCCPC
  • CBN introduces Nigeria’s new overnight rate
  • NALPGAM, LASTMA team up for safer LPG transport in Lagos
  • NSIB introduces new conditions of service
  • NDPC probes alleged CAC data breach
  • Customs seize N93m goods in Adamawa
  • Nasarawa speaker awards N60m scholarships
Facebook Twitter Instagram YouTube
AsheNewsAsheNews
  • Home
  • Agric

    Association urges members to boost catfish value

    April 17, 2026

    WFP spends $5M on shock response in Nigeria

    April 17, 2026

    Stakeholders push investment in Nigeria’s agribusiness

    April 16, 2026

    Nigeria faces 1m tonne palm oil deficit

    April 16, 2026

    WFP spends $5m on social protection in Nigeria

    April 16, 2026
  • Sci & Tech

    Nigerian freelancers face rising financial pressure

    April 17, 2026

    NDPC probes alleged CAC data breach

    April 17, 2026

    Airtel temporarily suspends credit services

    April 17, 2026

    First lady to launch ECoN initiative in Kano

    April 17, 2026

    NBTE declares AI core to technical education

    April 17, 2026
  • Health

    Family planning lowers maternal mortality by 30%

    April 17, 2026

    PCN seals 598 drug outlets in Kaduna

    April 17, 2026

    Foundation deploys health officers in Abia

    April 17, 2026

    UNILAG medicine faculty targets clinical innovation

    April 16, 2026

    Parasite free world unrealistic – FUTA professor

    April 16, 2026
  • Environment

    NSIB introduces new conditions of service

    April 17, 2026

    LAWMA cracks down on environmental violations in Alimosho

    April 17, 2026

    FG hands over 132 housing units to Kwara

    April 17, 2026

    SON hosts workshop on motor energy standards

    April 16, 2026

    Nigeria pushes for better water, sanitation

    April 15, 2026
  • Hausa News

    Otti plans 250-room 5-star hotel in Umuahia

    April 11, 2026

    Anti-quackery task force seals 4 fake hospitals in Rivers

    August 29, 2025

    [BIDIYO] Yadda na lashe gasa ta duniya a fannin Ingilishi – Rukayya ‘yar shekara 17

    August 6, 2025

    A Saka Baki, A Sasanta Saɓani Tsakanin ‘Yanjarida Da Liman, Daga Muhammad Sajo

    May 21, 2025

    Dan majalisa ya raba kayan miliyoyi a Funtuwa da Dandume

    March 18, 2025
  • More
    1. Business/Banking & Finance
    2. Politics/Elections
    3. Entertainments & Sports
    4. International
    5. Investigation
    6. Law & Human Rights
    7. Africa
    8. ACCOUNTABILITY/CORRUPTION
    9. Hassan Gimba
    10. Column
    11. Prof. Jibrin Ibrahim
    12. Prof. M.K. Othman
    13. Defense/Security
    14. Education
    15. Energy/Electricity
    16. Entertainment/Arts & Sports
    17. Society and Lifestyle
    18. Food & Agriculture
    19. Health & Healthy Living
    20. International News
    21. Interviews
    22. Investigation/Fact-Check
    23. Judiciary/Legislature/Law & Human Rights
    24. Oil & Gas/Mineral Resources
    25. Press Freedom/Media/PR/Journalism
    26. General News
    27. Presidency
    Featured
    Recent

    Nigerian freelancers face rising financial pressure

    April 17, 2026

    Airtime borrowing myths debunked by FCCPC

    April 17, 2026

    CBN introduces Nigeria’s new overnight rate

    April 17, 2026
  • About Us
    1. Contact Us
    2. Board Of Advisory
    3. Privacy Policy
    4. Ethics Policy
    5. Teamwork And Collaboration Policy
    6. Fact-Checking Policy
    7. Advertising
    Featured
    Recent

    Nigerian freelancers face rising financial pressure

    April 17, 2026

    Airtime borrowing myths debunked by FCCPC

    April 17, 2026

    CBN introduces Nigeria’s new overnight rate

    April 17, 2026
  • Media OutReach Newswire
    • Wire News
  • The Stories
AsheNewsAsheNews
Home»Science/Tech & Innovation/R&D»SideWinder APT group expanding threats to Middle East, Africa – Kaspersky
Science/Tech & Innovation/R&D

SideWinder APT group expanding threats to Middle East, Africa – Kaspersky

Abdallah el-KurebeBy Abdallah el-KurebeOctober 17, 2024Updated:October 17, 2024No Comments3 Mins Read
SideWinder APT group
Share
Facebook Twitter LinkedIn Pinterest Email

The Kaspersky Global Research and Analysis Team (GReAT) says it has detected that the SideWinder APT group is expanding its attack operations to impact high-profile entities and strategic infrastructure in the Middle East and Africa, utilising a previously unknown espionage toolkit called ‘StealerBot’.

As part of its ongoing monitoring of APT activities, Kaspersky discovered that recent campaigns by the SideWinder APT group were targeting high-profile entities and strategic infrastructures in various countries in the Middle East, Turkiye, as well as in Morocco and Djibouti in Africa. The campaign in general remains active and may target other victims.

SideWinder, also known as T-APT-04 or RattleSnake, is one of the most prolific APT groups that started operations in 2012. Over the years, it has primarily targeted military and government entities in Pakistan, Sri Lanka, China, and Nepal, as well as other sectors and countries in South and Southeast Asia. Recently, Kaspersky observed new waves of attacks, which have expanded to impact high-profile entities and strategic infrastructure in the Middle East and Africa.

Besides the geographical expansion, Kaspersky discovered that SideWinder is using a previously unknown post-exploitation toolkit called ‘StealerBot’. This is an advanced modular implant designed specifically for espionage activities and is currently used by the group as the main post-exploitation tool.

“In essence, StealerBot is a stealthy espionage tool that allows threat actors to spy on systems while avoiding easy detection. It operates through a modular structure, with each component designed to perform a specific function. Notably, these modules never appear as files on the system’s hard drive, making them difficult to trace. Instead, they are loaded directly into the memory. At the core of StealerBot is the ‘Orchestrator’, which oversees the entire operation, communicating with the threat actor’s command-and-control server, and coordinating the execution of its various modules”, says Giampaolo Dedola, lead security researcher at Kaspersky’s GReAT.

During its latest investigation, Kaspersky observed that StealerBot is performing a range of malicious activities, such as installing additional malware, capturing screenshots, logging keystrokes, stealing passwords from browsers, intercepting RDP (Remote Desktop Protocol) credentials, exfiltrating files, and more.

Kaspersky first reported on the group’s activities in 2018. This actor is known to rely on spear-phishing emails as its main infection method, containing malicious documents exploiting Office vulnerabilities and occasionally making use of LNK, HTML and HTA files that are contained in archives.

The documents often contain information obtained from public websites, which is used to lure the victim into opening the file and believing it to be legitimate. Kaspersky observed several malware families being used within parallel campaigns, including both custom-made and modified, publicly available RATs.

To mitigate threats related to APT activities, Kaspersky experts recommend equipping your organisation’s information security experts with the latest insights and technical details, such as from the Kaspersky Threat Intelligence Portal use robust solutions for endpoints and to detect advanced threats on the network, such as Kaspersky Next and Kaspersky Anti Targeted Attack Platform; educate employees to recognise cybersecurity threats such as phishing letters.

Kaspersky Kaspersky Global Research and Analysis Team SideWinder APT group StealerBot
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Abdallah el-Kurebe
  • Website
  • Facebook
  • Twitter
  • LinkedIn

Related Posts

Nigerian freelancers face rising financial pressure

April 17, 2026

NDPC probes alleged CAC data breach

April 17, 2026

Airtel temporarily suspends credit services

April 17, 2026

Leave A Reply Cancel Reply

Nigerian freelancers face rising financial pressure

April 17, 2026

Airtime borrowing myths debunked by FCCPC

April 17, 2026

CBN introduces Nigeria’s new overnight rate

April 17, 2026

NALPGAM, LASTMA team up for safer LPG transport in Lagos

April 17, 2026
About Us
About Us

ASHENEWS (AsheNewsDaily.com), published by PenPlus Online Media Publishers, is an independent online newspaper. We report development news, especially on Agriculture, Science, Health and Environment as they affect the under-reported rural and urban poor.

We also conduct investigations, especially in the areas of ASHE, as well as other general interests, including corruption, human rights, illicit financial flows, and politics.

Contact Info:
  • 1st floor, Dogon Daji House, No. 5, Maiduguri Road, Sokoto
  • +234(0)7031140009
  • ashenewsdaily@gmail.com
Facebook Twitter Instagram Pinterest
© 2026 All Rights Reserved. ASHENEWS Daily Designed & Managed By DeedsTech

Type above and press Enter to search. Press Esc to cancel.