Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: medium · affected_sectors: [] · au_impact: false

SideCopy

SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.

Attribute Detail
ATT&CK ID G1008
Aliases
Attribution India
Class state
Active since
ATT&CK entry created 2022-08-07
Techniques mapped 18

Attribution — as claimed

Contested in ATT&CK's own wording (hedged, or two plausible sponsors).

Known TTPs

Technique Name
T1016 System Network Configuration Discovery
T1036.005 Match Legitimate Resource Name or Location
T1059.005 Visual Basic
T1082 System Information Discovery
T1105 Ingress Tool Transfer
T1106 Native API
T1204.002 Malicious File
T1218.005 Mshta
T1518 Software Discovery
T1518.001 Security Software Discovery
T1566.001 Spearphishing Attachment
T1574.001 DLL

(First 12 of 18 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Ke3Chang — India-linked actor, same attribution class
  • Apt28 — India-linked actor, same attribution class
  • Apt29 — India-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1008 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.