SideCopy
Also reported as TAG-140, UNC2269, White Dev 55, Mocking Draco, Viridian Vortex and 4 other names. Linked to Pakistan by four sources.
Reports per quarter
Techniques seen in the last two years
- T1041 3 reports reports only
- T1047 3 reports reports only
- T1105 3 reports in ATT&CK
- T1204.002 3 reports in ATT&CK
- T1218.005 3 reports in ATT&CK
- T1547.001 3 reports reports only
- T1005 2 reports reports only
- T1012 2 reports reports only
- T1016 2 reports in ATT&CK
- T1057 2 reports reports only
Show all 56 techniques Show fewer
- T1059.003 2 reports reports only
- T1082 2 reports in ATT&CK
- T1129 2 reports reports only
- T1140 2 reports reports only
- T1204.001 2 reports reports only
- T1518.001 2 reports in ATT&CK
- T1566 2 reports reports only
- T1566.001 2 reports in ATT&CK
- T1571 2 reports reports only
- T1027 1 report reports only
- T1033 1 report reports only
- T1036 1 report reports only
- T1036.005 1 report in ATT&CK
- T1036.007 1 report reports only
- T1053.003 1 report reports only
- T1056.001 1 report reports only
- T1059 1 report reports only
- T1059.001 1 report reports only
- T1059.007 1 report reports only
- T1071 1 report reports only
- T1071.001 1 report reports only
- T1071.002 1 report reports only
- T1083 1 report reports only
- T1106 1 report in ATT&CK
- T1113 1 report reports only
- T1119 1 report reports only
- T1123 1 report reports only
- T1185 1 report reports only
- T1204 1 report reports only
- T1218 1 report reports only
- T1547 1 report reports only
- T1548.002 1 report reports only
- T1560.001 1 report reports only
- T1566.002 1 report reports only
- T1573.001 1 report reports only
- T1583.001 1 report reports only
- T1584.001 1 report in ATT&CK
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587.001 1 report reports only
- T1588.001 1 report reports only
- T1588.002 1 report reports only
- T1589.002 1 report reports only
- T1608.001 1 report in ATT&CK
- T1608.005 1 report reports only
- T1620 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-40539 KEV ransomware
Show all 40 CVEs Show fewer
- CVE-2021-44228 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20269 KEV ransomware
- CVE-2023-22515 KEV ransomware
- CVE-2023-22518 KEV ransomware
- CVE-2023-27350 KEV ransomware
- CVE-2023-27351 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-34048 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-40044 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46604 KEV ransomware
- CVE-2023-47246 KEV ransomware
- CVE-2023-4911 KEV
- CVE-2023-4966 KEV ransomware
- CVE-2023-50164
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor AllaKore (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NjRAT (Malware Family)
Show all 55 reports Show fewer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor watchtower-2023-eoy-report-en
-
AllaKore(d) the SideCopy Train
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AllaKore(d) the SideCopy Train
-
APT SideCopy Targeting Indian Government Entities - Analysis of the new version of ReverseRAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT SideCopy Targeting Indian Government Entities - Analysis of the new version of ReverseRAT
-
APT-36 Uses New TTPs and New Tools to Target Indian Governmental Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-36 Uses New TTPs and New Tools to Target Indian Governmental Organizations
-
Indian Governmental Organizations Targeted by APT-36
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Indian Governmental Organizations Targeted by APT-36
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
Transparent Tribe campaign uses new bespoke malware to target Indian government officials
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Transparent Tribe campaign uses new bespoke malware to target Indian government officials
-
Transparent Tribe campaign uses new bespoke malware to target Indian government officials
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Transparent Tribe campaign uses new bespoke malware to target Indian government officials
-
SideCopy Arsenal Update- Golang-based Linux stealth tools surface
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SideCopy Arsenal Update- Golang-based Linux stealth tools surface
-
SideCopy APT: from Windows to *nix - Telsy
The original link failed its last check. Original publisher Detailsfor SideCopy APT: from Windows to *nix - Telsy
-
SIDECOPY APT- From Windows to nix
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SIDECOPY APT- From Windows to nix
-
SideCopy APT- Connecting lures to victims, payloads to infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SideCopy APT- Connecting lures to victims, payloads to infrastructure
-
Taking Action Against Hackers in Pakistan and Syria
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taking Action Against Hackers in Pakistan and Syria
-
SideCopy organization's recent attack incident analysis using China-India current affairs news
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SideCopy organization's recent attack incident analysis using China-India current affairs news
-
Operation Armor Piercer: Targeted attacks in the Indian subcontinent using commercial RATs
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Armor Piercer: Targeted attacks in the Indian subcontinent using commercial RATs
-
Operation “Armor Piercer-” Targeted attacks in the Indian subcontinent using commercial RATs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation “Armor Piercer-” Targeted attacks in the Indian subcontinent using commercial RATs
-
APT Group Targets Indian Defense Officials Through Enhanced TTPs
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT Group Targets Indian Defense Officials Through Enhanced TTPs
-
APT Group Targets Indian Defense Officials Through Enhanced TTPs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group Targets Indian Defense Officials Through Enhanced TTPs
-
InSideCopy- How this APT continues to evolve its arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor InSideCopy- How this APT continues to evolve its arsenal
-
InSideCopy: How this APT continues to evolve its arsenal
The link to Mirror on Box failed its last check. Detailsfor InSideCopy: How this APT continues to evolve its arsenal
-
InSideCopy: How this APT continues to evolve its arsenal
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor InSideCopy: How this APT continues to evolve its arsenal
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation SideCopy!
-
Seqrite-WhitePaper-Operation-SideCopy
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Detailsfor Seqrite-WhitePaper-Operation-SideCopy
Newest first. Details opens the report in Explore.