Threadlinqs IntelligenceStart free

Threat actorPakistanTracked since 2026-05

SideCopy

Also known as:Transparent TribeAPT36APT-C-56Mythic LeopardProjectM

As of 2026-09-01, SideCopy is a Pakistan-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware, apt. Also known as Transparent Tribe, APT36, APT-C-56, Mythic Leopard. ATT&CK coverage spans 77 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1070.004 (File Deletion), T1071.001 (Web Protocols), T1082 (System Information Discovery).

Tracked threats
33 high
First seen
2026-05-29
Last seen
2026-07-27
ATT&CK techniques
77across 3 of 3 threats
Related CVEs
4Referenced by its activity
Attribution
PakistanNation or origin
Nation: Pakistan · 3 tracked threat(s) · Categories: THREAT_INTEL, MALWARE, APT

Activity timeline

SideCopy appears in 3 tracked threats between and ; the busiest month was 2026-07 with 2 reports.

ATT&CK techniques observed

77 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (16), Execution (11), Command and Control (8), Collection (7), Discovery (6), Resource Development (6)
  • T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
  • T1106 Native API — Executionobserved in 3 of 3 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 3 of 3 tracked threats
  • T1518.001 Security Software Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 3 of 3 tracked threats
  • T1564.001 Hidden Files and Directories — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 3 of 3 tracked threats
  • T1027.011 Fileless Storage — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
  • T1053.005 Scheduled Task — Persistenceobserved in 2 of 3 tracked threats
  • T1056.001 Keylogging — Collectionobserved in 2 of 3 tracked threats

Tracked threats

Related CVEs

4 CVEs referenced by tracked SideCopy activity