ATT&CKGroupsSideCopy

SideCopy

G1008

Threat group.View on attack.mitre.org

About this group

SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1016
System Network Configuration Discovery

SideCopy has identified the IP address of a compromised host.

T1036.005
Match Legitimate Resource Name or Location

SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool.

T1059.005
Visual Basic

SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`.

T1082
System Information Discovery

SideCopy has identified the OS version of a compromised host.

T1105
Ingress Tool Transfer

SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads.

T1106
Native API

SideCopy has executed malware by calling the API function `CreateProcessW`.

T1204.002
Malicious File

SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns.

T1218.005
Mshta

SideCopy has utilized `mshta.exe` to execute a malicious hta file.

T1518
Software Discovery

SideCopy has collected browser information from a compromised host.

T1518.001
Security Software Discovery

SideCopy uses a loader DLL file to collect AV product names from an infected host.

T1566.001
Spearphishing Attachment

SideCopy has sent spearphishing emails with malicious hta file attachments.

T1574.001
DLL

SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`.

T1584.001
Domains

SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware.

T1598.002
Spearphishing Attachment

SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts.

T1608.001
Upload Malware

SideCopy has used compromised domains to host its malicious payloads.

View all 16 procedure examples

Software2

Campaigns0

None recorded.

References1

  1. MalwareBytes SideCopy Dec 2021 Open source
    Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.