SideCopy
· Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
· Source: The MITRE Corporation
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 27/03/2026 01:14
- Updated at
- 27/03/2026 01:14
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 3 reports, 68 attack patterns (mitre), 15 malware, 6 sectors, 3 countries, 107 indicators, 1 vulnerabilities (cve)
Description
[SideCopy](https://attack.mitre.org/groups/G1008) is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. [SideCopy](https://attack.mitre.org/groups/G1008)'s name comes from its infection chain that tries to mimic that of [Sidewinder](https://attack.mitre.org/groups/G0121), a suspected Indian threat group.(Citation: MalwareBytes SideCopy Dec 2021)
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (3)
-
AlienVault Confidence 100 1 Malware 12 IOCs 12 Observables 1 APT
-
9 MITREs 3 Malwares 28 Observables 1 APT
-
14 MITREs 2 Malwares 21 Observables 1 APT
Attack patterns (MITRE) (68)
-
T1113 usesScreen Capture MITRE
-
T1204 usesUser Execution MITRE
-
T1583 usesAcquire Infrastructure MITRE
-
T1608.005 usesLink Target MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1127 usesTrusted Developer Utilities Proxy Execution MITRE
-
T1204.002 usesMalicious File MITRE
-
T1041 usesExfiltration Over C2 Channel MITRE
-
Email Accounts usesT1585.002 MITRE
-
T1547 usesBoot or Logon Autostart Execution MITRE
-
T1204.001 usesMalicious Link MITRE
-
T1112 usesModify Registry MITRE
Malware (15)
-
Xeno RAT usesFamily
-
Ares uses
-
Action RAT uses
-
XenoRAT usesFamily
-
Poseidon usesFamily
-
Spark RAT usesFamily
-
CurlBack RAT usesFamily
-
Margulas uses
-
AllaKore usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AuTo Stealer uses
-
Capra uses
-
PyInstaller usesFamily
Sectors (6)
-
Finance targets
-
Energy targets
-
Defense targets
-
Transportation targets
-
Government targets
-
Education targets
Countries (3)
-
Afghanistan targets
-
India targets
-
British Indian Ocean Territory targets
Indicators (107)
-
stix 100/100 Revoked· Valid until 24/12/2023 · Source: AlienVault
-
stix 100/100· Valid until 25/05/2027 · Source: AlienVault
-
www.cornerstonebeverly.orgindicatesstix 100/100 Revoked· Valid until 06/07/2024 · Source: AlienVault -
stix 100/100· Valid until 25/05/2027 · Source: AlienVault
-
stix 100/100 Revoked
SLF:Win32/LnkFileWithMshta.A
· Valid until 10/05/2023 · Source: AlienVault -
http://144.91.72.17:8080indicatesstix 100/100 Revoked· Valid until 10/05/2023 · Source: AlienVault -
stix 100/100 Revoked
SLF:Win32/LnkFileWithMshta.A SHA256 of 5be4e4884f4e021ba975cbed0a7e9c25
· Valid until 26/06/2024 · Source: AlienVault
Vulnerabilities (CVE) (1)
7.8
High
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file …
- Attack vector
- Local
- Published
- 24/08/2023
- Modified
- 27/05/2026