BroaderAspect is a .NET loader previously used by TAG-140 in campaigns targeting Indian government organizations. In the reported infection chain, victims were lured via a ClickFix-style social engineering workflow that spoofed the Indian Ministry of Defence and induced execution of a malicious script through mshta.exe. That execution led to the BroaderAspect loader, which established persistence and then installed and launched DRAT V2. The activity was assessed by Insikt Group as overlapping with SideCopy, an operational affiliate or subcluster linked to Transparent Tribe (APT36/ProjectM/MYTHIC LEOPARD), with moderate-confidence attribution to TAG-140. The broader campaign targeted Indian entities, including government and defense-related organizations, with reported expansion to organizations affiliated with India’s railway, oil and gas, and external affairs ministries. High-confidence behavior directly described for BroaderAspect is persistence establishment and staging/execution of the DRAT V2 remote access trojan as a subsequent payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...led to the execution of the BroaderAspect .NET loader... BroaderAspect establishes persistence and subsequent DRAT V2 installation and execution."
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET loader used in the intrusion chain to establish persistence and install/execute DRAT V2.
.NET loader used in the infection chain to establish persistence and install/execute DRAT V2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.