SideCopy
G10081 reportsaliases · SideCopy
1
Reports
1
Techniques
1
Tactics
5
Countries
100%
Hunt coverage
1
Aliases
Analyst assessment — key judgments
- Signature techniques: T1684 (Social Engineering).
- Primary targeting: CN, KP, KR, IR.
- Activity declining: 0 report(s) in last 30d vs 1 prior (-100%).
- Hunt coverage 100% of 1 observed techniques (0 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
DecliningLast 30d: 0 vs 1 prior (-100%)· first reported 2026-07-27 · last 2026-07-27
0
7d
0
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
Targeting lost
CNIRKPKRRUOverview
Analyst triage
Intelligence summary
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.(Citation: MalwareBytes SideCopy Dec 2021)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1684 · Social Engineeringconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|