Introduction
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East. SANS Windshift August 2018 objective-see windtail1 dec 2018 objective-see windtail2 jan 2019
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
Information pending cataloguing.
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- WindTail:
- WindTape:
Attribution and Evidence
Information pending cataloguing.
References
[1] MITRE ATT&CK MITRE ATT&CK entry [2] SANS Windshift August 2018 [3] objective-see windtail1 dec 2018 [4] objective-see windtail2 jan 2019