The modern cyber warfare landscape has evolved significantly as threat actors pivot toward simple yet highly effective and evasive malware. Threats like SideCopy have historically been surveillance and exfiltration of sensitive data from government officials and high-ranking personnel, but their strategic scope has recently broadened to include academic institutions. SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of a built-in system utility to execute malicious scripts and circumvent standard security protocols. This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure.
The SideCopy kill chain involves initial access via weaponized ZIP archives, followed by execution through a deceptive shortcut that triggers the initial malicious script execution. The HTA file contains an embedded a malicious library, and during execution the embedded DLL file is loaded into a built-in system utility through deserialization attack. The malware achieves persistence by modifying the Windows Registry to trigger a malicious batch file, i.e., a batch script. This script serves as a persistent mechanism for reboot execution. The threat actor establishes long-term persistence using Living-off-the-Land (LotL) techniques, exploiting BinaryFormatter to bypass security and re-animate malicious objects in memory.[/subscribe_to_unlock_form]
The modern cyber warfare landscape has evolved significantly as threat actors pivot toward simple yet highly effective and evasive malware. Threats like SideCopy have historically been surveillance and exfiltration of sensitive data from government officials and high-ranking personnel, but their strategic scope has recently broadened to include academic institutions. SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of a built-in system utility to execute malicious scripts and circumvent standard security protocols. This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure.
The SideCopy kill chain involves initial access via weaponized ZIP archives, followed by execution through a deceptive shortcut that triggers the initial malicious script execution. The HTA file contains an embedded a malicious library, and during execution the embedded DLL file is loaded into a built-in system utility through deserialization attack. The malware achieves persistence by modifying the Windows Registry to trigger a malicious batch file, i.e., a batch script. This script serves as a persistent mechanism for reboot execution. The threat actor establishes long-term persistence using Living-off-the-Land (LotL) techniques, exploiting BinaryFormatter to bypass security and re-animate malicious objects in memory.[emaillocker id="1283"]
Data exfiltration occurs through encrypted channels, transmitting stolen screenshots, files, and credentials to the C2 server. The SideCopy campaign lifecycle demonstrates a use of social engineering, anti-forensic techniques, and persistence mechanisms to evade detection and achieve its objectives. At the time of analysis, this campaign has been observed targeting academic institutions, expanding their strategic scope beyond government officials and high-ranking personnel. This expansion in targeting may indicate a wider impact on defenders, potentially affecting various sectors beyond those initially targeted.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Command & Control | E1105 | Ingress Tool Transfer |
The following reports contain further technical details:
[/emaillocker]