SideCopy.pdf
ID: c27bbc47-1fb2-4e03-a459-ec5dcc6e1fc1
STIX ID: report--c27bbc47-1fb2-4e03-a459-ec5dcc6e1fc1
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2021-07-02
Last Modified Date: 2021-07-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos details an active SideCopy APT campaign targeting Indian subcontinent government and military users; attackers use LNK/HTA/MSI and other delivery vectors with decoy documents and honeytraps to deploy a mix of custom and commodity RATs (CetaRAT, Allakore, njRAT, DetaRAT, ReverseRAT, MargulasRAT, ActionRAT, Lilith, Epicenter) and modular plugins (file manager, browser credential stealers, keyloggers, Golang ‘Nodachi’) to harvest credentials (including Kavach MFA data), enumerate/exfiltrate files, and maintain persistent C2 infrastructure with geofencing and victim logging — the report includes code snippets, infection-chain diagrams, targeting observations, and detection/mitigation guidance.
