SideCopy
Aliases: None listed
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.
Open interactive actor investigation
ATT&CK techniques
T1614
System Location DiscoveryT1518.001
Security Software DiscoveryT1584.001
DomainsT1105
Ingress Tool TransferT1016
System Network Configuration DiscoveryT1608.001
Upload MalwareT1106
Native APIT1059.005
Visual BasicT1518
Software DiscoveryT1566.001
Spearphishing AttachmentT1574.002
DLL Side-LoadingT1204.002
Malicious FileT1082
System Information DiscoveryT1598.002
Spearphishing AttachmentT1036.005
Match Legitimate Name or LocationT1218.005
Mshta
System Location DiscoveryT1518.001
Security Software DiscoveryT1584.001
DomainsT1105
Ingress Tool TransferT1016
System Network Configuration DiscoveryT1608.001
Upload MalwareT1106
Native APIT1059.005
Visual BasicT1518
Software DiscoveryT1566.001
Spearphishing AttachmentT1574.002
DLL Side-LoadingT1204.002
Malicious FileT1082
System Information DiscoveryT1598.002
Spearphishing AttachmentT1036.005
Match Legitimate Name or LocationT1218.005
Mshta