NEW: Group Profiler — instant APT intel lookup. Try it →

SideCopy

G1008 Pakistan MITRE ATT&CK →

Overview

SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.

Naming & attribution

SideCopy is tracked under 1 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here. Activity attributed since at least 2019.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1614 System Location Discovery — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Sidewinder India — 12 shared techniques (35% overlap)
  • TA2541 — 9 shared techniques (26% overlap)
  • Windshift — 7 shared techniques (25% overlap)
  • Naikon China — 6 shared techniques (25% overlap)
  • WIRTE — 8 shared techniques (24% overlap)
  • Tropic Trooper China — 10 shared techniques (22% overlap)

TTPs — 16 techniques across 7 tactics

Reconnaissance

Resource Development

Initial Access

Execution

Stealth

Command and Control

Tools & malware (2)

AuTo Stealer · Action RAT

Reporting (1)