Cyber Strategies Of Transparent Tribe & SideCopy Vs India
ID: 8fdae869-21d4-5234-9756-816823d57486
STIX ID: report--8fdae869-21d4-5234-9756-816823d57486
Feed Name: Cyble Blog
CRIL discovered a SideCopy APT campaign targeting South Asian (primarily Indian) universities that uses spammed ZIPs with malicious LNK files to launch mshta and download HTA payloads that decode loader DLLs (PreBotHTta.dll / PreBotHta.dll) and deploy Remote Access Trojans (ReverseRAT and Action RAT); the campaign implements DLL sideloading, persistence via startup folders and registry Run keys, antivirus-specific workflows, USB data collection, and communicates with identified C2 domains and IPs (e.g., reviewassignment.online, dns1.indianblog.xyz, 64.188.27.144).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
