Windshift
Also known as: Bahamut
Overview
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.
Naming & attribution
Windshift is tracked under 2 names across the industry. It uses 19 documented ATT&CK techniques — more than 51% of the 174 groups tracked here. Activity attributed since at least 2017.
| Name | First reported by |
|---|---|
| Bahamut | Karim, T |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1036.001Invalid Code Signature — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
TTPs — 19 techniques across 6 tactics
Initial Access
-
T1189Drive-by Compromise -
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link -
T1566.003Spearphishing via Service
Execution
-
T1047Windows Management Instrumentation -
T1059.005Visual Basic -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027Obfuscated Files or Information -
T1036Masquerading -
T1036.001Invalid Code Signature
Discovery
-
T1033System Owner/User Discovery -
T1057Process Discovery -
T1082System Information Discovery -
T1518Software Discovery -
T1518.001Security Software Discovery
Command and Control
-
T1071.001Web Protocols -
T1105Ingress Tool Transfer
Tools & malware (1)
WindTail
Reporting (3)
- Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2) — Wardle, Patrick
- Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 1) — Wardle, Patrick
- TRAILS OF WINDSHIFT — Karim, T