RAZOR TIGER is a suspected Indian state-sponsored APT group known for Spearphishing attacks against government and military entities in South Asia.
Analyst brief
RAZOR TIGER (also known as SideWinder) is a suspected Indian nation-state threat actor active since at least 2012. They primarily target government, military, and private sector entities in China, Pakistan, Nepal, and Afghanistan. Their core TTPs include extensive Spearphishing (Attachment/Link) for reconnaissance and initial access, leveraging exploits like CVE-2017-11882 for execution, establishing persistence via Registry Run Keys, and using tools like Koadic for C2 over Web Protocols. Defenders should prioritize monitoring for malicious email attachments exploiting known Office vulnerabilities, unusual Mshta.exe execution, and subsequent PowerShell payload deployments.
RAZOR TIGER
SideWinderRattlesnakeAPT-C-17
nation-state
An actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian company. To spread the malware, they use unique implementations to leverage the exploits of known vulnerabilities (such as CVE-2017-11882) and later deploy a Powershell payload in the final stages.
Detect Automated Exfiltration and block suspicious network activity.
FAQ2
What is the primary method used by RAZOR TIGER to gain initial access to targets?+
The actor uses Spearphishing (Attachment/Link), specifically leveraging malicious documents that exploit Microsoft Office vulnerabilities like CVE-2017-11882.
What payload does RAZOR TIGER typically deploy after gaining initial access?+
After gaining initial access, the actor typically deploys a PowerShell payload in the final stages, often using tools like Koadic for C2 communication.