>samit_hota
Back to adversary profiles

Threat Actor Dossier

Windshift (G0112): A Persistent Cyber Espionage Threat

G0112

Also tracked as Bahamut · 8 sectors targeted

Threat level
HIGH
Status
ACTIVE
Origin
Middle East (state-sponsored attribution); also links to Indian territory for "hack-for-hire" operations
Motivation
Espionage · Intelligence Gathering
Samit Hota·
Target Sectors
Government, Critical Infrastructure, Telecommunications, Energy, High-ranking Officials, Industrial Magnates, Human Rights Organizations, Political Activists
Associated Malware
WindTail, WindTape, DeadDrop, custom backdoors, RATs, Cobalt Strike, ChinaChopper, trojanized VPN apps, "SafeChat" (CoverIm)
#threat-actor#g0112

Overview

Windshift (G0112), also widely known by its alias Bahamut, is a highly sophisticated and persistent threat actor that has been active since at least 2017. Initially identified for targeting specific individuals for surveillance within government departments and critical infrastructure sectors across the Middle East, this group has evolved its operations and expanded its reach significantly.

The group’s primary motivation is cyber espionage, aiming to gather intelligence and support national security and strategic interests of its sponsoring nation. However, particularly under its Bahamut alias, the group is also characterized as a “hack-for-hire” mercenary organization, offering its services to a diverse range of clients and engaging in attacks for financial gain or to serve specific state interests.

Attribution for Windshift generally points to state-sponsored actors based in the Middle East. While this remains a consistent assessment for Windshift’s core activities, recent analyses of operations under the Bahamut alias suggest possible ties to Indian territory, with campaigns seemingly executed in the interest of a nation-state government.

Windshift’s typical targets include government agencies, telecommunications providers, and energy firms, with a primary geographical focus on the Middle East, including Gulf Cooperation Council (GCC) countries. Broader targeting under the Bahamut moniker extends to high-ranking government officials, industrial magnates, and individuals associated with human rights movements or supporting political separatism, such as Sikh separatism, across the Middle East, India, the UAE, and Saudi Arabia. The data sought and stolen ranges from strategic documents and confidential communications to proprietary technologies.

Tactics & Techniques

Windshift employs a wide array of tactics, techniques, and procedures (TTPs) designed for stealth, persistence, and effective data exfiltration across multiple platforms, including Windows, macOS, and mobile operating systems.

Initial access frequently relies on targeted spear-phishing campaigns, which may involve malicious attachments, embedded links in emails, or watering hole attacks. For mobile targets, they leverage meticulously crafted fake applications, often trojanized versions of legitimate VPN services or dummy chatting apps, distributed through malicious websites or direct spear-messaging via platforms like WhatsApp. They have also been observed installing malicious Mobile Device Management (MDM) profiles on iOS devices.

Once initial access is achieved, persistence is established through custom malware, backdoors, Remote Access Trojans (RATs), and the creation of LNK files in the Startup folder. Defense evasion is a hallmark of Windshift’s operations, utilizing revoked certificates to sign malware, employing anti-forensic tactics, and leveraging advanced anti-virus (AV) evasion techniques. The group is adept at crafting highly convincing fake websites, applications, and social media personas to lend legitimacy to their operations and deceive targets. They encrypt application strings and command and control (C2) communications, often using algorithms like AES in CBC or ECB mode, and hide multimedia files to avoid detection.

For credential access, Windshift uses credential theft, Pass-the-Hash techniques, and elaborate phishing pages designed to harvest login information. Discovery activities include leveraging Windows Management Instrumentation (WMI) to gather information about target machines, performing file and system information enumeration, and identifying usernames on compromised hosts. Lateral movement is facilitated through the exploitation of network vulnerabilities.

The group’s collection efforts are extensive, encompassing local account data, calendar information, contact lists, and SMS messages. Their mobile implants are particularly intrusive, capable of phone call and audio recording, keylogging, screenshots, and even video recording. Exfiltration typically occurs over encrypted channels, often utilizing HTTP for C2 communications, and sometimes through legitimate cloud services or FTP.

Notable Campaigns

Windshift has been associated with several significant campaigns demonstrating its evolving capabilities and targeting methodology.

Operation BULL and Operation ROCK: These campaigns involved the deployment of sophisticated malicious applications with extensive surveillance capabilities. The malware in these operations included features for location tracking, phone call and audio recording, SMS message exfiltration, file enumeration, system information enumeration, and video recording. Operation BULL specifically utilized AES in ECB mode and Blowfish for encryption, with keys ingeniously stored within the application’s launcher icon file, and also featured region-locking capabilities for its malicious apps.

Operation WindWalker: This large-scale campaign specifically targeted the telecommunications and energy sectors, indicating a focus on intelligence gathering from critical infrastructure.

Government Sector Attacks: Windshift has consistently compromised networks of various government agencies across the Middle East to steal confidential and strategic information.

Android Targeting Campaigns (2022-2023): Since early 2022, Windshift (under the Bahamut alias) has been actively targeting Android users with fake VPN applications such as trojanized versions of SoftVPN, OpenVPN, and SecureVPN. These spyware applications are designed to extract sensitive user data and specifically spy on popular messaging apps like WhatsApp, Facebook Messenger, Signal, Viber, and Telegram. In 2023, Cyfirma analysts identified further Android malware campaigns by Bahamut, distributing a dummy chatting application named “SafeChat” (also known as “CoverIm”) via WhatsApp, primarily targeting individuals in the South Asia region. These mobile campaigns have shown tactical similarities to the DoNot APT group, hinting at either shared methodologies or potential overlaps.

Associated Malware & Tools

Windshift possesses a robust and continuously improving arsenal of custom malware and leverages off-the-shelf tools to achieve its objectives.

Key custom malware families include:

  • WindTail (A and B): This backdoor for macOS systems is capable of installation, self-deletion, extensive file exfiltration, and establishing command and control communications.
  • WindTape: Another macOS malware, WindTape functions similarly to the Komplex OSX trojan, primarily designed to take screenshots of the compromised system and upload them to C2 servers.
  • DeadDrop: This is another identified malware family attributed to the group.

Beyond these, Windshift develops and utilizes various custom backdoors and Remote Access Trojans (RATs) to maintain long-term access to compromised networks. The group is also known for its ability to leverage zero-day vulnerabilities, with past instances including exploits for CVE-2017-0199 (Microsoft Office) and CVE-2018-20250 (WinRAR).

In addition to its custom tools, Windshift incorporates commercial and open-source tools into its operations, such as Cobalt Strike and ChinaChopper. Their mobile-focused operations heavily rely on bespoke Android spyware, often repackaged into trojanized legitimate applications or disguised as enticing new chat applications, which incorporate sophisticated keylogging and data exfiltration capabilities. Development practices involve using Visual Basic 6 (VB6) payloads and employing libraries like Ktor for efficient data transfer in Android malware.

Current Status

Windshift remains an Active and highly adaptive threat actor. The group has consistently demonstrated a high level of operational security, characterized by meticulous planning, patience, and a willingness to adapt tactics and infrastructure. It has been known to wait for extended periods, sometimes a year or more, before launching follow-up attacks, indicating significant resource investment and a long-term strategic outlook.

Recent activities observed in 2022 and 2023, particularly under the Bahamut alias, confirm the group’s ongoing operations and continued focus on mobile platforms and targets in the Middle East and South Asia. Their continued use of sophisticated phishing and fake application distribution methods, combined with their ability to develop and deploy tailored malware for various operating systems, underscores their persistent threat to government entities, critical infrastructure, and high-value individuals across their target regions. The group’s capacity for sustained campaigns and its reported links to both state-sponsored objectives and “hack-for-hire” services ensure its continued relevance and danger in the cyber threat landscape.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call