# SideCopy

> As of 2026-09-01, SideCopy is a Pakistan-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware, apt. Also known as Transparent Tribe, APT36, APT-C-56, Mythic Leopard. ATT&CK coverage spans 77 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1070.004 (File Deletion), T1071.001 (Web Protocols), T1082 (System Information Discovery).

- **Nation:** Pakistan
- **Tracked threats:** 3
- **Categories:** THREAT_INTEL, MALWARE, APT
- **Also known as:** Transparent Tribe, APT36, APT-C-56, Mythic Leopard, ProjectM
- **As of:** 2026-09-01

## ATT&CK techniques observed

77 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (16), Execution (11), Command and Control (8), Collection (7), Discovery (6), Resource Development (6).

- [T1070.004](https://intel.threadlinqs.com/technique/T1070.004) File Deletion — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 3 tracked threats
- [T1106](https://intel.threadlinqs.com/technique/T1106) Native API — Execution — observed in 3 of 3 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 3 of 3 tracked threats
- [T1518.001](https://intel.threadlinqs.com/technique/T1518.001) Security Software Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1547.001](https://intel.threadlinqs.com/technique/T1547.001) Registry Run Keys / Startup Folder — Persistence — observed in 3 of 3 tracked threats
- [T1564.001](https://intel.threadlinqs.com/technique/T1564.001) Hidden Files and Directories — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1566.001](https://intel.threadlinqs.com/technique/T1566.001) Phishing: Spearphishing Attachment — Initial Access — observed in 3 of 3 tracked threats
- [T1027.011](https://attack.mitre.org/techniques/T1027/011/) Fileless Storage — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 2 of 3 tracked threats
- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Collection — observed in 2 of 3 tracked threats

## Tracked threats

- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — HIGH
- [Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job Seekers](https://intel.threadlinqs.com/threat/TL-2026-1297) — HIGH
- [Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT 1.8.7 Against the Afghanistan Ministry of Finance](https://intel.threadlinqs.com/threat/TL-2026-0625) — HIGH

## Related CVEs

4 CVEs referenced by tracked SideCopy activity.

- [CVE-2024-39717](https://intel.threadlinqs.com/cve/CVE-2024-39717)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/SideCopy
