SideCopy is a Pakistan-linked cyber espionage threat cluster widely associated with the Transparent Tribe (APT36) umbrella and assessed by multiple researchers as aligned with Pakistani state interests. Active since at least 2019, the group has primarily targeted government, military, diplomatic, and other strategic entities across South Asia, with documented activity against Afghanistan and India. Reported targeting has included Afghanistan’s Ministry of Finance and provincial finance bodies, as well as Indian government-adjacent sectors such as railways and oil. SideCopy is known for spear-phishing-led initial access using localized and highly tailored lures, including archives containing malicious shortcut files, HTA payloads, and other attachment-based delivery mechanisms. The group has repeatedly abused legitimate Windows utilities such as mshta for fileless or low-artifact execution, used compromised infrastructure to host payloads, and employed DLL-based loaders and masquerading to blend malicious activity with legitimate processes. Observed tradecraft includes registry-based persistence, scheduled-task persistence, typosquatted or deceptive process naming, in-memory payload reconstruction, and other defense-evasion measures. Recent operations attributed to SideCopy deployed customized variants of the open-source Xeno RAT in espionage campaigns against Afghan government finance targets. These intrusions used Pashto-language lures and realistic decoy documents, indicating prior reconnaissance and target familiarization. Reported payload capabilities in SideCopy-linked campaigns include remote command execution, data theft, keylogging, screenshot capture, clipboard monitoring, network tunneling, and modular loading of additional components. SideCopy has also been associated with other malware families used in South Asian targeting, including CurlBack RAT, Spark RAT, CrimsonRAT, MeshAgent, and FalseCub in adjacent reporting. The group’s operational pattern is consistent with long-term intelligence collection rather than disruptive or financially motivated crime. SideCopy is best understood as a sub-cluster or subgroup within the broader Transparent Tribe/APT36 ecosystem, sharing overlapping infrastructure patterns, phishing tradecraft, and regional targeting priorities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
59 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage campaign targeting Afghanistan's government finance apparatus, including the Ministry of Finance and provincial government employees, using spear-phishing and Xeno RAT.
Conducting a targeted cyber espionage campaign against Afghan government networks, specifically the Afghan Ministry of Finance, using spear-phishing with localized Pashto-language lures to deliver a fileless XenoRAT infection chain and establish persistent remote access.
Conducting a spear-phishing campaign against Afghanistan government finance entities and Pashto-speaking officials using Xeno RAT for remote access, persistence, monitoring, and data exfiltration.
Conducting a spear-phishing campaign dubbed Operation XENOFISCAL targeting Afghanistan's Ministry of Finance, provincial revenue and finance directorates, Pashto-speaking government officials, and provincial-level government employees; also previously attributed to attacks targeting sectors in India.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.