Cyber Security News

SideWinder Hacker Group Target Government & Military Using WarHawk Tool

Zscaler ThreatLabz found a new backdoor called ‘WarHawk’ being used by the SideWinder APT threat group to target entities in Pakistan.

The SideWinder group goes by the names Rattlesnake, Hardcore Nationalist, RAZOR TIGER, T-APT-04, and APT-C-17, with a history of targeting government, military, and businesses throughout Asia, particularly Pakistan.

“The newly discovered WarHawk backdoor contains various malicious modules that deliver Cobalt Strike, incorporating new TTPs such as KernelCallBackTable injection and Pakistan Standard Time zone check in order to ensure a victorious campaign,” Zscaler ThreatLabz said.

The Working of WarHawk Backdoor

Reports say the ‘WarHawk’ backdoor consists of four modules such as:

  • Download & Execute Module
  • Command Execution Module
  • File Manager InfoExfil Module
  • UploadFromC2 Module

Researchers discovered that the ISO file hosted on the legitimate website of Pakistan’s National Electric Power Regulatory Authority “nepra[.]org[.]pk” which can indicate a compromise of their web server.

National Electric Power Regulatory Authority Website

It disguises itself as a legit application to lure unsuspecting victims into execution. Also, WarHawk decrypts a set of API & DLL names using a String Decryption Routine which takes the Encrypted Hex Bytes as an input and then subtracts each byte with the Key: “0x42” in order to decrypt the string.

WarHawk Backdoor disguises as legit applications

The download & execute module is responsible for downloading and executing additional payloads from the remote URL provided by the CnC server.

The command execution module is accountable for the execution of system commands on the infected machine received from the Command & Control. Subsequently, the File Manager InfoExfil module gathers and sends the File Manager information by primarily sending across a Module initiation request to the CnC server.

In the UploadFromC2 module, it is a new feature added in the latest WarHawk Backdoor, allowing the threat actor to upload files on the infected machine from the Command and Control Server.

SideWinder Network Infrastructure

Researchers say the following are the indicators that help out in determining that the campaign is targeted at Pakistan, ISO files hosted on Pakistan’s National Electric Power Regulatory Authority website, threat actors released by Pakistan’s Cabinet Division used as a lure, and the time zone check for “Pakistan Standard Time” that makes sure that the malware is only executed under Pakistan Standard Time.

“The SideWinder APT Group is continuously evolving their tactics and adding new malware to their arsenal in order to carry out successful espionage attack campaigns against their targets,” concludes the report.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago