Windshift

Also known as: Bahamut, Windshift, WindShift, Windy Phoenix

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East. SANS Windshift August 2018 objective-see windtail1 dec 2018 objective-see windtail2 jan 2019

🧭 ATT&CK G0112

Introduction

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East. SANS Windshift August 2018 objective-see windtail1 dec 2018 objective-see windtail2 jan 2019

Activities and Tactics

Information pending cataloguing.

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • WindTail:
  • WindTape:

Attribution and Evidence

Information pending cataloguing.

References

[1] MITRE ATT&CK MITRE ATT&CK entry [2] SANS Windshift August 2018 [3] objective-see windtail1 dec 2018 [4] objective-see windtail2 jan 2019