NOVEMBER 5, 2025

RAZOR TIGER, also known as SideWinder (APT-C-17, Rattlesnake, T-APT-04), is an advanced persistent threat (APT) actor that has operated for many years since at least 2012. Public and industry reporting has typically assessed the actor as being connected to Indian state interests focused on cyber-espionage activity, specifically targets in South Asia and surrounding areas. The RAZOR TIGER actor has changed its tradecraft, expanded into new sectors like maritime and logistics, and updated its malware arsenal to evade defenders.
The group’s consistent focus on Pakistan, China, Nepal, Bangladesh, Sri Lanka, and other South Asian countries is consistent with geopolitical rivalries and regional security issues. The group’s motivation is squarely focused on gathering intelligence to effectively meet national defense and foreign policy objectives.
RAZOR TIGER’s ability to shift and modify TTPs seems to be consistent with worldwide APT TTPs detailed in the 2024-2025 intel reports. To highlight some elements:
012–2016: Early phishing and credential theft operations, targeting South Asian government and defense organizations.
2017–2019: Expanded targeting of telecommunication networks, military networks, with a stronger emphasis on persistence (DLL side-loading techniques).
2020–2022: Utilization of cloud-hosted lures and expose enterprise services.
2023–2025: Extended targeting into maritime, logistical, and nuclear supporting areas; employed new implants with less detectable exfiltration channels.
Crime and threat intelligence from the past two years reflect how RAZOR TIGER has kept up with the changing global threat landscape:
Use of living-off-the-land techniques to limit reliance on signature-based detection of malware.
Use of a cloud resource for C2 to become much more commonplace, similar to how APT groups are increasingly adopting commercial platforms.
Increasing targeting of critical infrastructure, especially maritime and logistics, to support regional priorities.
RAZOR TIGER continues to be one of the most active South Asian espionage actors, incorporating outdated exploit techniques with ongoing evolution of those tactics. Its continued activity raises several strategic concerns for governments, corporate and critical infrastructure:
Defensive Recommendations:
RAZOR TIGER showcases the resilience and flexibility of a state-aligned APT. After more than a decade of transitioning from botched phishing attacks to sophisticated cloud-based espionage attacks, the resiliency of South Asian cyber-espionage eco-systems is demonstrated. For the defenders, at least the takeaway is clear; organizations must remain vigilant for the long-haul, untether themselves from the notion of layered defense, and share intelligence as quickly as this ecosystem of groups.
You can download and review the sheet for all the details!

Take control of your digital security with an exclusive demo of our powerful threat management platform.