Activity timeline
SideCopy appears in 3 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
- T1106 Native API — Executionobserved in 3 of 3 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 3 of 3 tracked threats
- T1518.001 Security Software Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 3 of 3 tracked threats
- T1564.001 Hidden Files and Directories — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 3 of 3 tracked threats
- T1027.011 Fileless Storage — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
- T1053.005 Scheduled Task — Persistenceobserved in 2 of 3 tracked threats
- T1056.001 Keylogging — Collectionobserved in 2 of 3 tracked threats
Tracked threats
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job SeekersHIGH
- Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT 1.8.7 Against the Afghanistan Ministry of FinanceHIGH