Researchers reported that the SideCopy espionage group targeted Indian defence organizations and armed forces personnel with spear-phishing campaigns using military-themed and honeytrap lures, including DRDO procurement documents, foreign assignment selections, personal photos, and reports about clashes involving soldiers. Across multiple campaigns, the attackers delivered malicious archives, disguised LNK files, and template-injection documents exploiting CVE-2017-11882, then used mshta.exe to retrieve remote HTA payloads, display decoy content, and establish persistence through VBS scripts, BAT files, and registry Run entries.
The intrusion chains deployed several remote-access tools, including MargulasRAT, Action RAT variants, and a newly observed .NET-based RAT, while also abusing the legitimate credwiz.exe binary for DLL sideloading. Investigators said the malware exfiltrated files from user directories, collected host information, and communicated with command-and-control infrastructure over ports such as 1443, 2443, and 3443, with some payload URLs hidden behind TinyURL links and others hosted on domains including elfinindia[.]com. The activity was tied to SideCopy operations active since 2019 and was assessed as closely aligned with, or possibly a subdivision of, Transparent Tribe based on overlapping tradecraft, infrastructure, and targeting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
A June 2023 Seqrite report described an ongoing SideCopy campaign targeting the Indian defence sector through phishing attachments and malicious URLs carrying disguised LNK files. The infection chains used MSHTA to fetch HTA payloads from elfinindia[.]com and deployed two Action RAT variants plus a newly observed .NET-based RAT.
Team Cymru analyzed a 2023 SideCopy spear-phishing campaign targeting India's Ministry of Defence and found it deployed Action RAT alongside a modified AllaKore RAT. The report also documented 18 Indian victims on Action RAT infrastructure, 236 victims on AllaKore infrastructure, and management activity tied to Pakistani mobile-provider IPs and Proton VPN nodes, strengthening the assessment of Pakistani-linked operations.
In April 2023, attackers targeted the Defence Ministry using the theme "Saudi Arabia Delegation with Indian Armed Forces Medical Officials." Seqrite linked the activity's infrastructure and tradecraft to SideCopy.
QiAnXin analyzed a recent SideCopy espionage campaign targeting Indian defense-related entities with ZIP archives containing malicious LNK files themed around Indian Ministry of Defense documents. The infection chain used mshta-delivered HTA and JavaScript payloads, in-memory DLL loading, antivirus-aware execution logic, and ultimately deployed a modified AllaKore RAT or a newer C++ payload.
Seqrite said another March 2023 SideCopy lure used the theme "Advisory on Grant of Risk & Hardship Allowance JCOs & ORs." This reflected continued spear-phishing against Indian military-related targets.
Seqrite reported that a similar SideCopy infection chain targeted DRDO in March 2023 using the decoy "HVAC Air Conditioning Design Basis Report" for its K4 Missile Clean Room. The activity was part of the group's continued targeting of Indian defence organizations.
QiAnXin reported a suspected SideCopy campaign that used the death of Indian Chief of Defence Staff Bipin Rawat as a lure in malicious documents targeting South Asia. The attack chain exploited CVE-2017-0199 for remote template injection, loaded a DOCX with malicious DDE fields, and executed PowerShell and VBS downloaders from attacker-controlled infrastructure.
QiAnXin reported that the primary analyzed sample, associated with filenames such as Int-Report-Poonch.exe and Wvie.exe, was a 270336-byte C# executable created on this date. The sample downloaded encrypted payloads from mojochamps.com and led to MargulasRAT deployment.
QiAnXin's RedDrip team identified a new SideCopy campaign using Indian military and geopolitical lure themes, including reports about clashes between terrorists and soldiers in India. The phishing chain used a C# downloader disguised as an image file, TinyURL-obfuscated payload links, and ultimately deployed MargulasRAT.
Cisco Talos began tracking the actor behind the campaign as a separate intrusion set named SideCopy APT. Talos associated the group with malware families including CetaRAT, ReverseRAT, MargulasRAT, AllakoreRAT, and multiple C# plugins.
In September 2020, Quick Heal disclosed Operation SideCopy as an espionage campaign using malspam LNK files, mshta-delivered HTA payloads, DLL sideloading via credwiz.exe, and RATs including winms.exe and sihostt.exe. Quick Heal assessed the actor was likely linked to or a subdivision of Transparent Tribe rather than SideWinder.
Seqrite documented a 2020 Operation SideCopy campaign targeting Indian government and critical infrastructure entities with spear-phishing lures including an Army Welfare Education Society scholarship form and later COVID-19 vaccination themes. The activity used spoofed LNK/HTA chains and SFX archives to deploy NJRat and a custom C# implant called ReverseRAT, which provided staged payload delivery, persistence, screenshot capture, self-update, and self-kill capabilities.
Quick Heal said Operation SideCopy had been active since early 2019, targeting Indian defence organizations, defence forces, and armed forces personnel with espionage-focused malware and lures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
seqrite.com
Open sourceseqrite.com
Open sourceteam-cymru.com
Open sourceti.qianxin.com
Open sourceti.qianxin.com
Open sourceti.qianxin.com
Open sourceseqrite.com
Open sourceseqrite.com
Open sourcesebdraven.medium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.