SideCopy

MITRE ATT&CK: G1008 View on attack.mitre.org

Aliases: SideCopy

First seen
2019-01-01 00:00:00
Origin
PK
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Related IoCs
6 (5 malicious)
Last IoC activity
2026-09-02 00:35:18
Profile updated
2026-07-07 12:00:51

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:in country_code:af

Context

SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.

Recent IoC activity

5 malicious indicators in Maltiverse are attributed to SideCopy (G1008). The 5 most recently updated:

TypeIndicatorUpdatedSources
hostname ssynergy.in 2026-09-03 2
hostname halterarks.co.uk 2026-09-03 1
hostname kcps.edu.in 2026-09-02 2
file sample a6d9022eff8fc6e0915d90a1fa8ceec29240f1dbd61f8f94182ef4c1371858cf 2026-05-29 1
file sample 6adde4444f2a249e027d3a234ce7c4071d4e4da1abcc89ea8059878ede7a4d38 2026-05-22 1

Detection coverage

  • 302 Sigma rules

Malware & tools used

  • System Location Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Domains (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Upload Malware (attack-pattern)
  • Native API (attack-pattern)
  • Visual Basic (attack-pattern)
  • Software Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • DLL (attack-pattern)
  • Malicious File (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Mshta (attack-pattern)
  • Action RAT (malware)
  • AuTo Stealer (malware)

Reports & references

  • seqrite.com — Operation Sidecopy (report)
  • blog.malwarebytes.com — Sidecopy Apt Connecting Lures To Victims Payloads To Infrastructure (report)
  • telsy.com — Sidecopy Apt From Windows To Nix (report)
  • Cisco Talos — Sidecopy (report)
  • about.fb.com — Taking Action Against Hackers In Pakistan And Syria (report)
  • sebdraven.medium.com — Copy Cat Of Apt Sidewinder 1893059Ca68D (report)
  • MITRE ATT&CK — G1008 (report)
  • malwarebytes.com — Sidecopy Apt Connecting Lures To Victims Payloads To Infrastructure (report)

External references