SideCopy’s Multi-platform Onslaught: Leveraging WinRAR Zero-Day and Linux Variant of Ares RAT
ID: 031e7869-28db-5e2a-99d4-955f6d1fd1d3
STIX ID: report--031e7869-28db-5e2a-99d4-955f6d1fd1d3
Feed Name: Seqrite Blog
Threat Score
SEQRITE Labs details multiple active SideCopy campaigns (linked to APT36) targeting Indian government and defense organizations, using phishing lures and the WinRAR zero-day CVE-2023-38831 to deliver multi-platform RATs (Windows AllaKore/DRat/Key RAT and a Linux Ares-based agent); the report includes technical infection chains, C2 and domain reuse, IOC lists (hashes, IPs, URLs), MITRE mappings, and an attribution assessment with defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
