Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Twitter Feed - nextronresearch - 17-06-2026

0
Medium
Published: Thu Jun 18 2026 (06/18/2026, 03:19:07 UTC)
Source: AlienVault OTX General

Description

SideCopy (APT36/Transparent Tribe) has initiated a targeted attack campaign against Indian defense personnel using a malicious lure disguised as a 'Minutes Of Meeting' document. The attack uses a double-extension .docx.lnk file to execute a PowerShell stager that deploys a Remote Access Trojan named pdfdocs. The malware establishes persistence via the HKCU Run registry key. Initial delivery components show very low detection rates by antivirus engines, increasing only at the final executable stage. The campaign replicates tactics from previous operations by this threat actor.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/18/2026, 20:35:07 UTC

Technical Analysis

This campaign by SideCopy employs a social engineering lure—a double-extension shortcut file named 'Minutes Of Meeting.docx.lnk'—which runs a PowerShell stager (pdfdocs.bat) from a nested folder while displaying a clean decoy document to the victim. The stager then deploys a Remote Access Trojan (pdfdocs) that achieves persistence by adding itself to the HKCU Run registry key. Detection rates for the initial components are very low (0/66 for the decoy document, 1/61 for the stager), with only the final payload detected moderately (35/71). The attack targets Indian defense personnel and uses known adversary tactics consistent with SideCopy's previous campaigns.

Potential Impact

The attack enables unauthorized remote access to compromised systems via the pdfdocs RAT, potentially allowing the adversary to maintain persistence, execute commands, and exfiltrate data. The low detection rates at initial stages increase the likelihood of successful compromise. Targeting Indian defense personnel indicates a high-value espionage objective. No known exploits in the wild are reported for this campaign, but the RAT's presence poses a significant threat to confidentiality and operational security.

Mitigation Recommendations

No official patch or fix is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize double-extension files and suspicious email attachments, restrict execution of PowerShell scripts from untrusted locations, and monitor for persistence mechanisms such as unexpected entries in the HKCU Run key. Endpoint detection and response solutions should be updated to detect the pdfdocs RAT and associated stager components. Given the low initial detection rates, layered defenses and behavioral monitoring are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://x.com/nextronresearch/status/2067230614424600844"]
Adversary
SideCopy
Pulse Id
6a3363abf0061625f1a7b54a
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashad7e4f47f9ddb2f97c8818d89374a82278922bac1bc41209ecd0b5ad027dcb45
hashb3007c3b0f140df374a6756215bde55409124822203d309dcc82e10aa8115a91
hashdb1cb4aaee4ad2f1b2907b2c2d3393544a6a05f9a4d8819eb0078606402c416c
hashe9f8a7e6275c263d2a1c9c5c9725addbf484c77c1aa8387093c16f50ebdc11ab

Threat ID: 6a345308f198dc38c17d113f

Added to database: 6/18/2026, 8:20:24 PM

Last enriched: 6/18/2026, 8:35:07 PM

Last updated: 6/19/2026, 3:00:02 AM

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses