Threat group.View on attack.mitre.org
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
SideCopy has identified the IP address of a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool. |
| T1059.005 Visual Basic |
SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`. |
| T1082 System Information Discovery |
SideCopy has identified the OS version of a compromised host. |
| T1105 Ingress Tool Transfer |
SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads. |
| T1106 Native API |
SideCopy has executed malware by calling the API function `CreateProcessW`. |
| T1204.002 Malicious File |
SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns. |
| T1218.005 Mshta |
SideCopy has utilized `mshta.exe` to execute a malicious hta file. |
| T1518 Software Discovery |
SideCopy has collected browser information from a compromised host. |
| T1518.001 Security Software Discovery |
SideCopy uses a loader DLL file to collect AV product names from an infected host. |
| T1566.001 Spearphishing Attachment |
SideCopy has sent spearphishing emails with malicious hta file attachments. |
| T1574.001 DLL |
SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`. |
| T1584.001 Domains |
SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware. |
| T1598.002 Spearphishing Attachment |
SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts. |
| T1608.001 Upload Malware |
SideCopy has used compromised domains to host its malicious payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.