Threat Advisory

SideCopy Uses MSHTA-driven Execution and RAT Deployment

Threat: Malware
Threat Actor Name: SideCopy
Targeted Region: Asia
Alias: Fringe Leopard
Threat Actor Region: Pakistan
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The modern cyber warfare landscape has evolved significantly as threat actors pivot toward simple yet highly effective and evasive malware. Threats like SideCopy have historically been surveillance and exfiltration of sensitive data from government officials and high-ranking personnel, but their strategic scope has recently broadened to include academic institutions. SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of a built-in system utility to execute malicious scripts and circumvent standard security protocols. This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure.

The SideCopy kill chain involves initial access via weaponized ZIP archives, followed by execution through a deceptive shortcut that triggers the initial malicious script execution. The HTA file contains an embedded a malicious library, and during execution the embedded DLL file is loaded into a built-in system utility through deserialization attack. The malware achieves persistence by modifying the Windows Registry to trigger a malicious batch file, i.e., a batch script. This script serves as a persistent mechanism for reboot execution. The threat actor establishes long-term persistence using Living-off-the-Land (LotL) techniques, exploiting BinaryFormatter to bypass security and re-animate malicious objects in memory.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The modern cyber warfare landscape has evolved significantly as threat actors pivot toward simple yet highly effective and evasive malware. Threats like SideCopy have historically been surveillance and exfiltration of sensitive data from government officials and high-ranking personnel, but their strategic scope has recently broadened to include academic institutions. SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of a built-in system utility to execute malicious scripts and circumvent standard security protocols. This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure.

The SideCopy kill chain involves initial access via weaponized ZIP archives, followed by execution through a deceptive shortcut that triggers the initial malicious script execution. The HTA file contains an embedded a malicious library, and during execution the embedded DLL file is loaded into a built-in system utility through deserialization attack. The malware achieves persistence by modifying the Windows Registry to trigger a malicious batch file, i.e., a batch script. This script serves as a persistent mechanism for reboot execution. The threat actor establishes long-term persistence using Living-off-the-Land (LotL) techniques, exploiting BinaryFormatter to bypass security and re-animate malicious objects in memory.[emaillocker id="1283"]

Data exfiltration occurs through encrypted channels, transmitting stolen screenshots, files, and credentials to the C2 server. The SideCopy campaign lifecycle demonstrates a use of social engineering, anti-forensic techniques, and persistence mechanisms to evade detection and achieve its objectives. At the time of analysis, this campaign has been observed targeting academic institutions, expanding their strategic scope beyond government officials and high-ranking personnel. This expansion in targeting may indicate a wider impact on defenders, potentially affecting various sectors beyond those initially targeted.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.001 Phishing Spearphishing Attachment
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Anti-Static Analysis B0032 Executable Code Obfuscation
Anti-Static Analysis E1027 Obfuscated Files or Information
Command & Control E1105 Ingress Tool Transfer

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu