NEW: Group Profiler — instant APT intel lookup. Try it →

Windshift

Also known as: Bahamut

Overview

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.

Naming & attribution

Windshift is tracked under 2 names across the industry. It uses 19 documented ATT&CK techniques — more than 51% of the 174 groups tracked here. Activity attributed since at least 2017.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
BahamutKarim, T

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1036.001 Invalid Code Signature — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Sidewinder India — 13 shared techniques (36% overlap)
  • APT37 North Korea — 12 shared techniques (33% overlap)
  • Molerats — 8 shared techniques (30% overlap)
  • TA2541 — 10 shared techniques (27% overlap)
  • Confucius — 8 shared techniques (27% overlap)
  • Elderwood China — 6 shared techniques (27% overlap)

TTPs — 19 techniques across 6 tactics

Tools & malware (1)

WindTail

Reporting (3)