SmartStateIndia
News

Seqrite uncovers APT ‘Operation SideCopy’ targeting India’s Defence Forces

Seqrite Operation SideCopy

Seqrite, the cybersecurity products and solutions brand of Quick Heal Technologies has uncovered a new Advanced Persistent Threat (APT) targeting India’s Defence Forces. Dubbed as ‘Operation Sidecopy’, threat actors behind this campaign were found misleading the security community by copying Tactics, Techniques, and Procedures (TTPs) that point at the Sidewinder APT group. However, researchers at Seqrite have discovered strong evidence of ‘Operation Sidecopy’, having potential links with Pakistan backed – Transparent Tribe group. This is a breakthrough discovery making Seqrite the first cybersecurity brand to expose the real identity of these threat actors.

Post revelation, Seqrite alerted the Government authorities to take precautionary measures. Researchers at Seqrite suspect that China could be leveraging Pakistan-based APT groups to barge in and gather intelligence from India that can benefit them in the on-going India-China conflicts. They further warned that these attacks can put intelligence agencies at risk of losing sensitive information which can be leveraged by both the neighbouring countries. This may happen directly via data exfiltration or indirectly via compromising an individual and compelling them to share confidential data.

Active since early 2019, ‘Operation Sidecopy’ has been using infecting vectors like LNK file, template injection, and equation editor vulnerability to target Indian defence forces. For Command & Control, it has been using Contabo GmbH, the most common hosting providers favoured by Transparent Tribe. According to Seqrite researchers, the malicious actors have been continuously developing malware modules and deploying the updated versions after analyzing the victim’s data and environment. Interestingly, these attackers were even keeping track of malware detected by a system’s AV and hence updating them immediately so that there is no trace left for further investigation.

Uncovering the attack

A couple of months ago, Seqrite’s next-generation behavioural detection technology alerted on a few processes running executable HTML files from non-reputed websites. In addition, the researchers noticed that offending processes had interesting names such as “Defence Production Policy 2020.docx.lnk”. When combined, these factors served as the trigger for advance investigation. Upon probing further, Seqrite researchers found that these attacks were targeted at Indian defence units and armed forces’ individuals.

The attack started with the victim receiving LNK files in the form of compressed ZIP/RAR via phishing emails. Since these files appeared to have realistic names and icons as if they are directly coming from the Government of India, the victims are likely to consider them authentic and get tricked into opening them.

Once opened, the malware runs in the system’s memory, and gradually downloads / installs other components, eventually stealing user data and uploading it to attacker-controlled servers. This attack made use of DLL-Sideloading technique (aka Black-White technique). A Microsoft signed a legitimate system process (credwiz.exe) was used to run malware via sideloading technique. After infiltrating the victim’s machine, the malware immediately restarts the victim’s device, to clear initial infection traces.

Related posts

Informa Markets in India introduces AMWC India 2023: The Transformative Aesthetic and Anti-Aging Event of the Year

SSI Bureau

NXP India, in collaboration with Startup India, MeitY & FabCI, IIT Hyderabad Kickstarts Season-2 of Semiconductor Incubation and Acceleration Program for Tech Startups

SSI Bureau

o9 Solutions Launches Supply Sensing to Help Companies Predict, Assess and Mitigate Supply Disruptions

SSI Bureau

20 comments

Arzzbd March 7, 2024 at 5:16 pm

atorvastatin 80mg brand atorvastatin for sale online order generic atorvastatin 10mg

Reply
Iixmoe March 18, 2024 at 11:36 pm

buy generic ciprofloxacin – buy ciprofloxacin 500 mg generic erythromycin 500mg oral

Reply
Fbejfa March 19, 2024 at 5:26 am

how to buy valacyclovir – valacyclovir usa buy acyclovir 800mg without prescription

Reply
Rfzomm March 21, 2024 at 2:16 am

stromectol 3mg online – suprax oral tetracycline oral

Reply
Hhfixk March 22, 2024 at 11:02 pm

lasix for sale online – buy generic candesartan capoten oral

Reply
Aaqzuo March 23, 2024 at 5:05 am

cost acillin order monodox pills buy amoxicillin cheap

Reply
Nqkrek March 26, 2024 at 5:00 am

zidovudine cost – allopurinol 100mg pills purchase zyloprim generic

Reply
Svjxxb March 29, 2024 at 9:09 am

clozapine usa – order clozapine generic pepcid ca

Reply
Tavlwy March 31, 2024 at 4:55 am

atarax sale – order nortriptyline 25mg pill endep usa

Reply
Jlaqzr April 3, 2024 at 7:00 pm

buy amoxicillin tablets – cephalexin 125mg us oral ciprofloxacin

Reply
Mylahd April 9, 2024 at 2:56 am

order cleocin 300mg generic – terramycin 250mg usa chloramphenicol buy online

Reply
Zpjpms April 15, 2024 at 3:05 am

clarinex brand – cost clarinex 5mg ventolin 2mg pill

Reply
Zejbdy April 17, 2024 at 4:36 am

micronase usa – buy micronase 2.5mg without prescription dapagliflozin 10mg ca

Reply
Cewrca April 19, 2024 at 4:26 am

repaglinide 1mg pill – jardiance 25mg brand jardiance 25mg us

Reply
Fusxlj April 21, 2024 at 5:27 am

order glucophage generic – buy generic precose over the counter buy acarbose 50mg online

Reply
Iloyne April 24, 2024 at 12:54 am

purchase ketoconazole generic – buy butenafine without prescription sporanox 100 mg tablet

Reply
Csoxdy April 24, 2024 at 3:17 am

order generic semaglutide 14 mg – buy glucovance tablets buy DDAVP online

Reply
Iuncwh April 26, 2024 at 2:31 am

buy digoxin 250 mg online – buy furosemide 40mg online purchase lasix generic

Reply
Juvrvf April 27, 2024 at 6:13 am

buy famvir tablets – order famciclovir 250mg online cheap buy valcivir pills for sale

Reply
Xehadf April 28, 2024 at 4:21 am

cheap hydrochlorothiazide – buy cheap amlodipine zebeta 5mg pills

Reply

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More