logo

Notorious SideCopy APT group sets sights on India’s DRDO

ID: d6a7bf64-9dc2-5617-8298-2d763f9296b9

STIX ID: report--d6a7bf64-9dc2-5617-8298-2d763f9296b9

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

SideCopy APT (attributed to Pakistan) ran a targeted spearphishing campaign against India's DRDO using a malicious LNK inside a ZIP that invoked mshta to run staged HTA loaders which decode and load DLLs in memory, perform DLL sideloading of a malicious DUser.dll (ActionRAT), deploy an AuTo Stealer, establish persistence via registry run keys, and beacon to a disclosed C2; the report includes technical TTPs and IOCs (file hashes, malicious URLs, and C2 IP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.