The Global Research and Analysis Team (GReAT) at Kaspersky Lab has discovered that the cyber group SideWinder is using a new espionage tool known as StealerBot. The attackers primarily target large organizations and strategic infrastructure in the Middle East and Africa. This was reported to Gazeta.Ru by Kaspersky Lab's press service.

SideWinder (also known as T-APT-04, RattleSnake) first came to the attention of cybersecurity experts in 2012 and remains one of the most active cyber groups. The group's primary targets were military and government institutions in Pakistan, Sri Lanka, China, and Nepal, as well as organizations in other sectors and countries across South and Southeast Asia.

The group has since expanded its geographical scope of attacks to the Middle East and Africa. Additionally, SideWinder has employed a previously unknown tool called StealerBot. This is an advanced modular implant specifically designed for espionage. StealerBot can perform a range of tasks, including installing additional malware, taking screenshots, logging keystrokes, stealing passwords from browsers, intercepting RDP (Remote Desktop Protocol) credentials, and extracting files.

“StealerBot allows attackers to monitor systems while being difficult to detect. It operates through a modular structure, where each component performs a specific function. These modules never appear as files on the hard drive, making them harder to trace, as they are loaded directly into memory,” comments Dmitry Galov, head of Kaspersky GReAT in Russia.