logo

SideCopy’s Multi-platform Onslaught: Leveraging WinRAR Zero-Day and Linux Variant of Ares RAT

ID: 031e7869-28db-5e2a-99d4-955f6d1fd1d3

STIX ID: report--031e7869-28db-5e2a-99d4-955f6d1fd1d3

Feed Name: Seqrite Blog

Threat Score
90/100

Date Published: 2023-11-06

Date Updated: 2026-04-30

Author: Sathwik Ram Prakki

...
...

SEQRITE Labs details multiple active SideCopy campaigns (linked to APT36) targeting Indian government and defense organizations, using phishing lures and the WinRAR zero-day CVE-2023-38831 to deliver multi-platform RATs (Windows AllaKore/DRat/Key RAT and a Linux Ares-based agent); the report includes technical infection chains, C2 and domain reuse, IOC lists (hashes, IPs, URLs), MITRE mappings, and an attribution assessment with defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.