Transparent Tribe & SideCopy: A Dangerous Cyber Alliance Targeting India
ID: ea76d324-478b-5e36-b110-07f67ebcfde2
STIX ID: report--ea76d324-478b-5e36-b110-07f67ebcfde2
Feed Name: securityonline.info
Cyble Research and Intelligence Labs (CRIL) discovered an active SideCopy/Transparent Tribe campaign targeting India that uses spammed ZIP attachments containing malicious LNK files to launch mshta.exe, download and execute HTA content which constructs an in-memory DLL (PreBotHTta.dll) and ultimately deploys Remote Access Trojans (ReverseRAT/Action RAT). The adversary leverages Base64-encoded payloads, ActiveX dynamic invocation, AV-aware persistence techniques, and a malicious website hosting lure files, demonstrating a sophisticated, adaptable APT campaign against public and private sector targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
