Exploring the SideWinder APT Group’s DNS Footprint
The SideWinder advanced persistent threat (APT) group, also known as “T-APT-04” or “RattleSnake,” has been around for more than a decade now. So it is not surprising for its network to have grown over the years. In fact, as many as 100 domains have been identified as SideWinder indicators of compromise (IoCs) as of 15 October 2024.1
The WhoisXML API research team dove deep into the existing SideWinder network using DNS intelligence by expanding the current IoC list and found: