Threat Advisory

SideCopy APT's Targeted Attack on Indian Defence Sector

Threat: Malicious Campaign
Criticality: High
[subscribe_to_unlock_form]

Summary:

SideCopy APT has launched a fresh attack campaign targeting the Indian Defence sector, utilizing phishing emails with malicious attachments and URLs. The infection vector leads to the deployment of two distinct Action RAT payloads and a novel .NET-based RAT. Three infection chains leverage themes related to DRDO’s “Invitation Performa” a honeytrap lure, and the Indian Military with the theme “Selection of Officers for Foreign Assignments.”  SideCopy, known for consistently targeting Indian Defence since 2019, employs three infection chains leading to payloads hosted on the domain. Archive files, masquerading as DOCX, PNG, and PDF, contain malicious LNK files triggering remote HTA file execution via MSHTA on the mentioned domain.[/subscribe_to_unlock_form]

Summary:

SideCopy APT has launched a fresh attack campaign targeting the Indian Defence sector, utilizing phishing emails with malicious attachments and URLs. The infection vector leads to the deployment of two distinct Action RAT payloads and a novel .NET-based RAT. Three infection chains leverage themes related to DRDO’s “Invitation Performa” a honeytrap lure, and the Indian Military with the theme “Selection of Officers for Foreign Assignments.”  SideCopy, known for consistently targeting Indian Defence since 2019, employs three infection chains leading to payloads hosted on the domain. Archive files, masquerading as DOCX, PNG, and PDF, contain malicious LNK files triggering remote HTA file execution via MSHTA on the mentioned domain.[emaillocker id="1283"]

Observations reveal the deployment of two Action RAT variants and a new .NET-based RAT supporting 18 C2 commands. Action RAT downloads a larger variant that exfiltrates documents and images within specific directories. The legitimate ‘credwiz.exe’ file is exploited for sideloading both RATs. SideCopy’s C2 infrastructure exhibits known hostnames, aligning with established TTPs over the years. This year, heightened activity from SideCopy targeting India's defence sector is evident, employing spear-phishing campaigns and honeytrap lures. The use of honey traps by Pakistani agents raises concerns about potential damage. The analysis underscores the necessity of proactive measures to counter such cyber espionage tactics.

Threat Profile:

 

References:

Eventus Security Threat Research & Development Team

[/emaillocker]
crossmenu