SideCopy

Also known as: SideCopy

SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy’s name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group. MalwareBytes SideCopy Dec 2021

🌍 Country Pakistan
🧭 ATT&CK G1008

Introduction

SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy’s name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group. MalwareBytes SideCopy Dec 2021

Activities and Tactics

Country of Origin: πŸ‡΅πŸ‡° Pakistan

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • CyberGate:
  • Cyber Eye RAT:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Pakistan Additional attribution information pending cataloguing.

References

[1] mitre-attack [2] MalwareBytes SideCopy Dec 2021 Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.