Uptime Hamster: 10d 10h 53mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza WindShift

WindShift

0 incidentes 0 paises 0 sectores apt ME Ultimo: -
Aliases: Windy Phoenix, URPAGE, EHDEVEL, WINDSHIFT, The White Company, G0112, InPage zero-day, Malicious MDM, la defensa de infraestructuras críticas, aunque no se han identificado sistemas específicos afectados
Ver en IntelTracker → APTTrail →
WindShift is a nation-state cyber espionage group that first emerged in early 2018, attributed with high confidence to a Middle Eastern authority. The group's primary motivation is intelligence gathering, and they distinguish themselves through highly targeted attacks on government sectors and critical infrastructure. They employ custom malware, such as OSX.WindTail for macOS and APK.Bahamut for Android, delivered via spear-phishing campaigns. WindShift is notable for its focused targeting of specific, often high-profile individuals within defense and government entities across the Middle East and South Asia. The group is also known by the alias Windy Phoenix.

Aliases del actor

Windy PhoenixURPAGEEHDEVELWINDSHIFTThe White CompanyG0112InPage zero-dayMalicious MDMla defensa de infraestructuras críticasaunque no se han identificado sistemas específicos afectados

Actores similares

The White Companyapt · 1whiteelephantactor · 1themx0ndayactor · 1white-companyactor · 1thegentlemenransomware · 504handalaransomware · 175other-actorsactor · 72the-gentlemenactor · 700day-syndicateactor · 5brotherhoodransomware · 3
Motivacion