AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
SideCopy
Aliases: None listed
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.
Open interactive actor investigation
ATT&CK techniques
System Location DiscoveryT1518.001
Security Software DiscoveryT1584.001
DomainsT1105
Ingress Tool TransferT1016
System Network Configuration DiscoveryT1608.001
Upload MalwareT1106
Native APIT1059.005
Visual BasicT1518
Software DiscoveryT1566.001
Spearphishing AttachmentT1574.002
DLL Side-LoadingT1204.002
Malicious FileT1082
System Information DiscoveryT1598.002
Spearphishing AttachmentT1036.005
Match Legitimate Name or LocationT1218.005
Mshta
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-nameModule 4 — Collection Sources
Cyber Threat Intelligence (CTI) · explicit-nameModule 5 — Analysis Techniques Tradecraft
Cyber Threat Intelligence (CTI) · explicit-nameModule 7 — Intelligence Products Sharing
Cyber Threat Intelligence (CTI) · explicit-nameModule 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · explicit-nameModule 2 — Reconnaissance and attack-surface mapping
Red Team & Offensive Security · explicit-nameModule 6 — Active Directory and identity attack paths
Red Team & Offensive Security · explicit-nameModule 13 — Red-team infrastructure and operations
Red Team & Offensive Security · explicit-nameNetwork behavior, protocols, and configuration recovery
Malware Analysis & Reverse Engineering · explicit-nameShared responsibility, governance, and service ownership
Cloud Security · explicit-namePosture management, exposure, vulnerabilities, attack paths, and validation
Cloud Security · explicit-nameCloud incident response, forensics, containment, and recovery
Cloud Security · explicit-name