TF-MAL-elf.unidentified_005
📛 Threat Title
Malware family: Unidentified 005 (Sidecopy)
Description
ThreatFox malware family `elf.unidentified_005`. Printable name: Unidentified 005 (Sidecopy).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Threat Group Cards: A Threat Actor Encyclopedia APT group: SideCopy ... Last change to this card: 16 August 2025 Download this actor card in PDF or JSON format ↑
-
web:assets.kpmg.com
the Difference. SideCopy is a Pakistan-linked APT group, active since 2019. It operates as a sub-cluster of Transparent Tribe (APT36), a known threat actor group engaged in cyber espionage across South Asia. APT36 typically targets Linux-based environments, while SideCopy focuses on Windows systems, using a range of Remote Access Trojans (RATs) and plugins to maintain persistence and extract ...
-
web:attack.mitre.org
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy 's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.
-
web:cyble.com
SideCopy originates from Pakistan and operates as an APT group. Learn more about SideCopy Threat Actor Profile origin, target country and more at Cyble!
-
web:gbhackers.com
A modified version of open-source XenoRAT, which was initially used by North Korean-linked groups, has been repurposed by SideCopy for HVNC, live microphone access, keylogging, and other espionage activities. The malware communicates with the C2 server (79.141.161.58:1256), suggesting a deep level of customization to evade detection.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Unidentified 005 (Sidecopy) malware family including references, samples and yara signatures.
-
web:threatmon.io
Sidecopy's attack demonstrates a high level of sophistication and underscores the importance of ongoing vigilance in the realm of cybersecurity. As a response to this threat, the ThreatMon Malware Research Team conducted a comprehensive technical analysis, aiming to dissect the attack from inception to execution.
-
web:ti.qianxin.com
Additionally, Sidecopy maintains its style of enriching its RAT code by obtaining code from the Internet, and has added the function of capturing browser passwords in the new DetaRAT based on open source projects. Conclusion The recent attack organized by Sidecopy is a continuation of the attacks that occurred in March.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.hivepro.com
Attack: A threat actor linked to Pakistan named SideCopy is capitalizing on WinRAR's CVE-2023-38831 vulnerability to target Indian government agencies. This security vulnerability facilitates distribution of various trojans, enabling attackers to gain remote access to compromised systems. The latest campaign is multi-platform and includes attacks designed to use an Ares RAT to infiltrate Linux ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.