SideCopy
MITRE ATT&CK: G1008 View on attack.mitre.org
Aliases: SideCopy
- First seen
- 2019-01-01 00:00:00
- Origin
- PK
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 6 (5 malicious)
- Last IoC activity
- 2026-09-02 00:35:18
- Profile updated
- 2026-07-07 12:00:51
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:in country_code:af
Context
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.
Recent IoC activity
5 malicious indicators in Maltiverse are attributed to SideCopy (G1008). The 5 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | ssynergy.in | 2026-09-03 | 2 |
| hostname | halterarks.co.uk | 2026-09-03 | 1 |
| hostname | kcps.edu.in | 2026-09-02 | 2 |
| file sample | a6d9022eff8fc6e0915d90a1fa8ceec29240f1dbd61f8f94182ef4c1371858cf | 2026-05-29 | 1 |
| file sample | 6adde4444f2a249e027d3a234ce7c4071d4e4da1abcc89ea8059878ede7a4d38 | 2026-05-22 | 1 |
Detection coverage
- 302 Sigma rules
Malware & tools used
- System Location Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Domains (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Upload Malware (attack-pattern)
- Native API (attack-pattern)
- Visual Basic (attack-pattern)
- Software Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- DLL (attack-pattern)
- Malicious File (attack-pattern)
- System Information Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Mshta (attack-pattern)
- Action RAT (malware)
- AuTo Stealer (malware)
Reports & references
- seqrite.com — Operation Sidecopy (report)
- blog.malwarebytes.com — Sidecopy Apt Connecting Lures To Victims Payloads To Infrastructure (report)
- telsy.com — Sidecopy Apt From Windows To Nix (report)
- Cisco Talos — Sidecopy (report)
- about.fb.com — Taking Action Against Hackers In Pakistan And Syria (report)
- sebdraven.medium.com — Copy Cat Of Apt Sidewinder 1893059Ca68D (report)
- MITRE ATT&CK — G1008 (report)
- malwarebytes.com — Sidecopy Apt Connecting Lures To Victims Payloads To Infrastructure (report)