Home/Threat Actor/SideCopy
Threat Actor

SideCopy

sidecopy · pakistan · active since 2019

SideCopy (APT-C-56 / TAG-117 / G1008) is a suspected Pakistan- aligned cyber-espionage cluster active since at least 2019 and publicly disclosed by Seqrite (Quick Heal) Threat Research Labs in September 2020 with seminal international-vendor disclosure by Cisco Talos in July 2021, widely assessed by vendor research to operate in alignment with Pakistani Inter-Services Intelligence (ISI) interests alongside Transparent Tribe / APT36 (already covered as mythic_leopard.yaml) within the broader Pakistani state-cyber ecosystem, with sustained joint operations against Indian government, defense, military (Indian Army, Navy, Air Force), DRDO, paramilitary, intelligence-services, and defense- academic-research targets, defined operationally by the signature attribution-misdirection tradecraft of copying SideWinder-style (India-aligned, already covered as sidewinder.yaml) tradecraft patterns in apparent false-flag operations (a relatively unusual explicit cluster-level false-flag investment), by the signature Action RAT + Reverse RAT + Margulas RAT toolkit, by rapid n-day-vulnerability weaponization (notably CVE-2023-38831 WinRAR within weeks of disclosure, CVE-2022-30190 Follina, CVE-2021-40444 MSHTML), and by high-fidelity Indian-military-themed social-engineering lures including fake Indian Army officer credentials, DRDO research papers, and ministry circulars.

pakistan confidence: high 19 aliases MITRE ATT&CK G1008 ↗

Profile

SideCopy (also tracked as APT-C-56, TAG-117 in Recorded Future taxonomy, and MITRE ATT&CK G1008) is a suspected Pakistan-aligned cyber-espionage cluster active since at least 2019 and publicly characterized in initial form by Seqrite (Quick Heal) Threat Research Labs in September 2020, with the seminal international- vendor disclosure by Cisco Talos in July 2021 ("InSideCopy: How This APT Continues to Evolve Its Arsenal"). The cluster is widely assessed to operate in alignment with Pakistani state intelligence interests, most commonly framed as Inter-Services Intelligence (ISI) tasking, the same Pakistani intelligence service that runs Transparent Tribe / APT36 (already covered as mythic_leopard.yaml). No formal government attribution event has been issued.

The cluster's name derives from its defining operational tradecraft: copying SideWinder-style (India-aligned, already covered as sidewinder.yaml) tradecraft patterns in what vendor research has assessed as an attempt at attribution misdirection. The mimicry attempts to make campaigns appear to be India-aligned operations (and therefore against Pakistani interests) when they are actually Pakistani operations against Indian targets. The attribution-misdirection pattern is operationally interesting because it represents an explicit cluster-level investment in false-flag tradecraft, a relatively unusual pattern among publicly-tracked state-aligned clusters and one that complicates defender attribution analysis.

The mimicry is not perfect: cluster- level operational signatures (distinct Action RAT / Reverse RAT / Margulas RAT toolkit, infrastructure patterns, victim-selection patterns) remain reliable attribution indicators that distinguish SideCopy from the actually-India-aligned SideWinder it imitates. A defining operational characteristic is sustained joint operations with Transparent Tribe / APT36. Documented infrastructure-and-victim overlap shows campaigns frequently use SideCopy-attributed implants alongside Transparent-Tribe- attributed implants against the same Indian victim sets.

The coordination pattern is the strongest publicly-available evidence for the broader Pakistani state-cyber ecosystem framing. Whether the coordination reflects centralized ISI tasking, decentralized cluster-to-cluster coordination, or shared contractor operations has been analytically open. The cleanest framing is that SideCopy and Transparent Tribe operate within the same Pakistani state-cyber ecosystem with substantial operational overlap but represent separable cluster identities based on toolkit and tradecraft differences.

Targeting focus is overwhelmingly directed at Indian government ministries, Indian Army (notably Northern Command and Eastern Command formations facing Pakistani and Chinese borders), Indian Navy, Indian Air Force, the Defence Research and Development Organisation (DRDO), paramilitary forces (Border Security Force, Central Reserve Police Force), Indian intelligence services, Indian state and central government entities, and Indian defense-academic research institutions. The Indian- military-and-defense focus is the cluster's dominant operational mission and aligns directly with broader ISI Pakistani- intelligence priorities. Selective targeting of Afghan, Bhutanese, Nepalese, Sri Lankan, and Bangladeshi entities has been documented but represents a small fraction of cluster operations.

Operationally the cluster's toolkit centers on three custom Windows remote-access-trojan families: Action RAT (the cluster's primary implant providing command execution, file collection, screenshot capture), Reverse RAT (a sibling implant with overlapping capability and different command-and-control patterns), and Margulas RAT (a newer implant first publicly disclosed by Cisco Talos in 2021). Additional tooling includes AllaKore RAT variants (a commercial RAT also used by other clusters, AllaKore-presence-alone insufficient for cluster attribution), DjvuHostSvc, NjRAT overlap, and Cobalt Strike Beacon for hands-on-keyboard operations. Initial-access tradecraft is predominantly spear-phishing with weaponized .lnk shortcuts, Microsoft Compiled HTML Help (.chm) decoy files, weaponized Office documents (CVE-2017-0199, CVE-2017-11882, CVE-2018-0798, CVE-2018-0802, CVE-2021-40444, CVE-2022-30190 Follina), and notably the rapid 2023 weaponization of CVE-2023-38831 (WinRAR RCE) within weeks of disclosure.

Lure themes include fake Indian Army officer credentials, DRDO research papers, ministry circulars, and Indian-government- themed PDFs, high-fidelity social-engineering content tailored to Indian military and government recipients. A handful of operational notes: First, the attribution-misdirection tradecraft (the SideWinder mimicry that gave the cluster its name) represents an unusually explicit cluster-level investment in false-flag tradecraft. Defender attribution analysis benefits from being aware of this pattern: SideWinder-style indicators in campaigns against Indian targets should be evaluated for the possibility of SideCopy misdirection rather than treated as automatic India-attribution indicators.

Second, the cluster's operational adjacency to Transparent Tribe / APT36 should be understood as substantive operational coordination within the same Pakistani state-cyber ecosystem rather than as cluster-identity ambiguity. The two clusters operate as separable but coordinated operational identities. Third, the cluster has not demonstrated 0day-development capability and primarily relies on rapid weaponization of disclosed n-day vulnerabilities, a pattern consistent with operational-maturity rather than top-tier capability development.

The August 2023 CVE-2023-38831 WinRAR weaponization within weeks of disclosure illustrates the operational tempo. Fourth, the cluster's continued operations through 2024-2025 despite substantial public attribution illustrate (consistent with the Star Blizzard, Sandworm, Pioneer Kitten, and Cadet Blizzard patterns in this corpus) that formal or research-grade attribution and public exposure do not necessarily produce operational pauses for state-aligned clusters.

Aliases

19
sidecopyside copyside_copyapt36 sub-clusterapt36_sub_clusterapt_36_sub_clustertransparent tribe adjacenttransparent_tribe_adjacentmythic leopard adjacentmythic_leopard_adjacentapt-c-56apt_c_56aptc56tag-117tag_117tag117g1008atk 240atk240

Notable Campaigns

9
2024-2025Continued Operations (2024-2025)
2023CVE-2023-38831 WinRAR Exploitation (2023)
2022-2024Indian Defense-Academic-and-Research Targeting (2022-2024)
2021Cisco Talos: InSideCopy, How This APT Continues to Evolve Its Arsenal (July 2021)
2020-2024Action RAT / Reverse RAT / Margulas RAT Signature Toolkit Evolution (2020-2024)
2020-2024Sustained Indian Government and Military Targeting (2020-2024)
2020-2024Joint Operations with Transparent Tribe / APT36 (2020-2024)
2020Seqrite (Quick Heal): SideCopy APT Operation (September 2020)
2019-2020Pre-Disclosure Indian-Targeting Operations (2019-2020)

Attribution & Reporting

Attributed by
Cisco TalosSeqrite Threat Research Labs (Quick Heal)Indian National Cyber Security CoordinatorIndian CERT-InESETMandiant / FireEyeRecorded Future Insikt GroupTrend MicroKaspersky GReATQiAnXin Threat Intelligence Center360 Threat Intelligence CenterSentinelOneCluster25CyfirmaSECUINFRA Falcon TeamMicrosoftGroup-IBK7 Computing
Key reporting
reportSeqrite (Quick Heal) Threat Research Labs: Operation SideCopy (September 2020), seminal cluster naming
reportCisco Talos: InSideCopy, How This APT Continues to Evolve Its Arsenal (July 2021), seminal international-vendor disclosure
reportCisco Talos: SideCopy and Transparent Tribe (February 2022), joint operations analysis
reportESET: Transparent Tribe Overview, Attacks Asia (March 2022), adjacent context
reportRecorded Future Insikt Group: TAG-117 SideCopy Pakistan (multiple years)
reportMandiant: Pakistani-Aligned Actor Targets Indian Defense Targets
reportSECUINFRA Falcon Team: SideCopy APT CVE-2023-38831 Exploitation (2023)
reportIndian CERT-In: SideCopy Activity Alerts (multiple years)
reportSeqrite: SideCopy APT, Still Going Strong (ongoing tracking)
reportQiAnXin Threat Intelligence Center: APT-C-56 SideCopy Tracking (Chinese-language)
reportSekoia: SideCopy Pakistan India Tracking (2023-2024)
reportCyfirma: SideCopy APT Tracking (2024)
reportCluster25: SideCopy Operational Profile (2022-2024)
reportMalpedia Actor Profile: SideCopy
reportMITRE ATT&CK Group G1008, SideCopy

Operational

State sponsor

Suspected Pakistan-aligned cyber-espionage cluster, widely assessed by vendor research (Cisco Talos seminal July 2021 disclosure "InSideCopy: How This APT Continues to Evolve Its Arsenal", Seqrite / Quick Heal Indian-CERT-relevant reporting, Indian National Cyber Security Coordinator advisories, ESET, Mandiant, Recorded Future, others) to operate in alignment with Pakistani state intelligence interests, most commonly framed as Inter-Services Intelligence (ISI) tasking, the same Pakistani intelligence service that runs Transparent Tribe / APT36 (already covered as mythic_leopard.yaml). Operational evidence suggests SideCopy frequently pairs with Transparent Tribe / APT36 in joint operations against the same Indian government, defense, and military victim categories, with the two clusters sharing infrastructure and victim selection patterns in many documented campaigns. Whether SideCopy is best understood as a Transparent Tribe / APT36 sub-cluster, a sibling cluster within the same ISI-aligned ecosystem, or a separate operational entity that coordinates operations has been analytically open, different vendors have framed the relationship differently.

The cleanest framing is that SideCopy and Transparent Tribe / APT36 operate within the same Pakistani state-cyber ecosystem with substantial operational overlap but represent separable cluster identities based on toolkit and tradecraft differences. The cluster's name derives from its apparent operational tradecraft of copying SideWinder-style (India-aligned, already covered) tradecraft patterns in what vendor research has assessed as an attempt at attribution misdirection, making campaigns appear to be India- aligned (and therefore against Pakistani interests) when they are actually Pakistani operations against Indian targets. No formal US, UK, EU, or other government attribution event has been issued.

Motivations
espionage, intelligence_gathering, geopolitical_collection, regional_adversary_targeting, cross_border_collection, india_intelligence_priority, defense_industrial_collection, attribution_misdirection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)26/60 · 43%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MARGULAS RATMARGULASRATMICROSOFT COMPILED HTML HELP ABUSEMSHTASIDECOPY CUSTOM DOWNLOADERSSIDEWINDER TRADECRAFT MIMICRY
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin