Twitter Feed - nextronresearch - 17-06-2026
SideCopy (APT36/Transparent Tribe) has initiated a targeted attack campaign against Indian defense personnel using a malicious lure disguised as a 'Minutes Of Meeting' document. The attack uses a double-extension .docx.lnk file to execute a PowerShell stager that deploys a Remote Access Trojan named pdfdocs. The malware establishes persistence via the HKCU Run registry key. Initial delivery components show very low detection rates by antivirus engines, increasing only at the final executable stage. The campaign replicates tactics from previous operations by this threat actor.
AI Analysis
Technical Summary
This campaign by SideCopy employs a social engineering lure—a double-extension shortcut file named 'Minutes Of Meeting.docx.lnk'—which runs a PowerShell stager (pdfdocs.bat) from a nested folder while displaying a clean decoy document to the victim. The stager then deploys a Remote Access Trojan (pdfdocs) that achieves persistence by adding itself to the HKCU Run registry key. Detection rates for the initial components are very low (0/66 for the decoy document, 1/61 for the stager), with only the final payload detected moderately (35/71). The attack targets Indian defense personnel and uses known adversary tactics consistent with SideCopy's previous campaigns.
Potential Impact
The attack enables unauthorized remote access to compromised systems via the pdfdocs RAT, potentially allowing the adversary to maintain persistence, execute commands, and exfiltrate data. The low detection rates at initial stages increase the likelihood of successful compromise. Targeting Indian defense personnel indicates a high-value espionage objective. No known exploits in the wild are reported for this campaign, but the RAT's presence poses a significant threat to confidentiality and operational security.
Mitigation Recommendations
No official patch or fix is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize double-extension files and suspicious email attachments, restrict execution of PowerShell scripts from untrusted locations, and monitor for persistence mechanisms such as unexpected entries in the HKCU Run key. Endpoint detection and response solutions should be updated to detect the pdfdocs RAT and associated stager components. Given the low initial detection rates, layered defenses and behavioral monitoring are recommended.
Affected Countries
British Indian Ocean Territory, India
Indicators of Compromise
- hash: ad7e4f47f9ddb2f97c8818d89374a82278922bac1bc41209ecd0b5ad027dcb45
- hash: b3007c3b0f140df374a6756215bde55409124822203d309dcc82e10aa8115a91
- hash: db1cb4aaee4ad2f1b2907b2c2d3393544a6a05f9a4d8819eb0078606402c416c
- hash: e9f8a7e6275c263d2a1c9c5c9725addbf484c77c1aa8387093c16f50ebdc11ab
Twitter Feed - nextronresearch - 17-06-2026
Description
SideCopy (APT36/Transparent Tribe) has initiated a targeted attack campaign against Indian defense personnel using a malicious lure disguised as a 'Minutes Of Meeting' document. The attack uses a double-extension .docx.lnk file to execute a PowerShell stager that deploys a Remote Access Trojan named pdfdocs. The malware establishes persistence via the HKCU Run registry key. Initial delivery components show very low detection rates by antivirus engines, increasing only at the final executable stage. The campaign replicates tactics from previous operations by this threat actor.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign by SideCopy employs a social engineering lure—a double-extension shortcut file named 'Minutes Of Meeting.docx.lnk'—which runs a PowerShell stager (pdfdocs.bat) from a nested folder while displaying a clean decoy document to the victim. The stager then deploys a Remote Access Trojan (pdfdocs) that achieves persistence by adding itself to the HKCU Run registry key. Detection rates for the initial components are very low (0/66 for the decoy document, 1/61 for the stager), with only the final payload detected moderately (35/71). The attack targets Indian defense personnel and uses known adversary tactics consistent with SideCopy's previous campaigns.
Potential Impact
The attack enables unauthorized remote access to compromised systems via the pdfdocs RAT, potentially allowing the adversary to maintain persistence, execute commands, and exfiltrate data. The low detection rates at initial stages increase the likelihood of successful compromise. Targeting Indian defense personnel indicates a high-value espionage objective. No known exploits in the wild are reported for this campaign, but the RAT's presence poses a significant threat to confidentiality and operational security.
Mitigation Recommendations
No official patch or fix is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize double-extension files and suspicious email attachments, restrict execution of PowerShell scripts from untrusted locations, and monitor for persistence mechanisms such as unexpected entries in the HKCU Run key. Endpoint detection and response solutions should be updated to detect the pdfdocs RAT and associated stager components. Given the low initial detection rates, layered defenses and behavioral monitoring are recommended.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://x.com/nextronresearch/status/2067230614424600844"]
- Adversary
- SideCopy
- Pulse Id
- 6a3363abf0061625f1a7b54a
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashad7e4f47f9ddb2f97c8818d89374a82278922bac1bc41209ecd0b5ad027dcb45 | — | |
hashb3007c3b0f140df374a6756215bde55409124822203d309dcc82e10aa8115a91 | — | |
hashdb1cb4aaee4ad2f1b2907b2c2d3393544a6a05f9a4d8819eb0078606402c416c | — | |
hashe9f8a7e6275c263d2a1c9c5c9725addbf484c77c1aa8387093c16f50ebdc11ab | — |
Threat ID: 6a345308f198dc38c17d113f
Added to database: 6/18/2026, 8:20:24 PM
Last enriched: 6/18/2026, 8:35:07 PM
Last updated: 6/19/2026, 3:00:02 AM
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.