A Pakistan-linked advanced persistent threat (APT) group known for targeting organizations in India and Afghanistan has been connected to a new phishing campaign that distributes the Action RAT malware.
Security researchers at Cyble have attributed the campaign to SideCopy, reporting that the operation primarily targets the Defence Research and Development Organization (DRDO), the research and development agency under India’s Ministry of Defence.
Active since at least 2019, SideCopy is a Pakistan-origin threat group recognized for mimicking attack techniques previously associated with SideWinder while deploying its own malware. Researchers have also identified operational similarities between SideCopy and Transparent Tribe.
The attack begins with carefully crafted spear-phishing emails designed to trick recipients into opening a malicious ZIP archive. Inside the archive is a Windows shortcut (.LNK) file disguised as documentation related to the K-4 ballistic missile, a missile system developed by DRDO.
When the shortcut file is executed, it downloads an HTML Application (HTA) from a remote server. While the victim is shown a decoy presentation to avoid raising suspicion, the attack silently installs the Action RAT backdoor in the background.
Once deployed, Action RAT collects information from the compromised system and establishes communication with a command-and-control (C2) server. The malware can execute attacker-issued commands, steal files from the infected device, and deploy additional malicious payloads when instructed.

Researchers also observed the use of a newly identified information-stealing malware named AuTo Stealer. The stealer is designed to search for and exfiltrate valuable data, including Microsoft Office documents, PDF files, databases, text files, and image files using either HTTP or TCP communication.
According to Cyble, the threat actor continues to refine its attack techniques while expanding its malware toolkit with new capabilities.
This is not the first campaign in which SideCopy has leveraged Action RAT against Indian targets. In December 2021, Malwarebytes reported attacks that used the same malware family to compromise multiple government ministries in Afghanistan, as well as a shared government computer in India, with the objective of stealing sensitive credentials.
The latest campaign follows another operation observed just one month earlier, in which SideCopy targeted Indian government organizations using a different remote access trojan known as ReverseRAT, highlighting the group’s continued focus on government and defense-related entities in the region.


