created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: medium · affected_sectors: [] · au_impact: false
SideCopy
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1008 |
| Aliases | — |
| Attribution | India |
| Class | state |
| Active since | — |
| ATT&CK entry created | 2022-08-07 |
| Techniques mapped | 18 |
Attribution — as claimed
Contested in ATT&CK's own wording (hedged, or two plausible sponsors).
Known TTPs
| Technique | Name |
|---|---|
T1016 |
System Network Configuration Discovery |
T1036.005 |
Match Legitimate Resource Name or Location |
T1059.005 |
Visual Basic |
T1082 |
System Information Discovery |
T1105 |
Ingress Tool Transfer |
T1106 |
Native API |
T1204.002 |
Malicious File |
T1218.005 |
Mshta |
T1518 |
Software Discovery |
T1518.001 |
Security Software Discovery |
T1566.001 |
Spearphishing Attachment |
T1574.001 |
DLL |
(First 12 of 18 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — India-linked actor, same attribution class
- Apt28 — India-linked actor, same attribution class
- Apt29 — India-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1008 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.