• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
sidecopy exploiting winrar flaw in attacks targeting indian government entities

SideCopy Exploiting WinRAR Flaw in Attacks Targeting Indian Government Entities

You are here: Home / General Cyber Security News / SideCopy Exploiting WinRAR Flaw in Attacks Targeting Indian Government Entities
November 7, 2023

The Pakistan-joined menace actor recognised as SideCopy has been observed leveraging the modern WinRAR security vulnerability in its attacks targeting Indian federal government entities to deliver numerous remote obtain trojans such as AllaKore RAT, Ares RAT, and DRat.

Organization security agency SEQRITE described the campaign as multi-platform, with the attacks also created to infiltrate Linux systems with a suitable edition of Ares RAT.

SideCopy, lively because at minimum 2019, is recognised for its attacks on Indian and Afghanistan entities. It is suspected to be a sub-group of the Clear Tribe (ak APT36).

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“Both of those SideCopy and APT36 share infrastructure and code to aggressively focus on India,” SEQRITE researcher Sathwik Ram Prakki reported in a Monday report.

Cybersecurity

Before this May perhaps, the team was connected to a phishing marketing campaign that took benefit of lures connected to India’s Defence Investigation and Progress Group (DRDO) to produce facts-stealing malware.

Since then, SideCopy has also been implicated in a established of phishing attacks concentrating on the Indian protection sector with ZIP archive attachments to propagate Action RAT and a new .NET-based mostly trojan that supports 18 various instructions.

The new phishing campaigns detected by SEQRITE entail two various attack chains, each individual targeting Linux and Windows running systems.

SideCopy Exploiting WinRAR Flaw

The previous revolves close to a Golang-primarily based ELF binary that paves the way for a Linux variation of Ares RAT that is capable of enumerating information, taking screenshots, and file downloading and uploading, between many others.

The second campaign, on the other hand, entails the exploitation of CVE-2023-38831, a security flaw in the WinRAR archiving tool, to set off the execution of destructive code, main to the deployment of AllaKore RAT, Ares RAT, and two new trojans identified as DRat and Essential RAT.

“[AllaKore RAT] has the performance to steal technique facts, keylogging, take screenshots, add & download data files, and just take the distant entry of the sufferer machine to deliver commands and upload stolen information to the C2,” Ram Prakki explained.

Cybersecurity

DRat is capable of parsing as many as 13 commands from the C2 server to get technique details, obtain and execute supplemental payloads, and accomplish other file functions.

The focusing on of Linux is not coincidental and is likely motivated by India’s determination to substitute Microsoft Windows with a Linux taste termed Maya OS across govt and protection sectors.

“Growing its arsenal with zero-day vulnerability, SideCopy continuously targets Indian defense businesses with different distant obtain trojans,” Ram Prakki said.

“APT36 is increasing its Linux arsenal frequently, where sharing its Linux stagers with SideCopy is noticed to deploy an open up-resource Python RAT known as Ares.”

Uncovered this posting attention-grabbing? Adhere to us on Twitter  and LinkedIn to study far more special written content we put up.


Some sections of this write-up are sourced from:
thehackernews.com

Previous Post: «experts warn of ransomware hackers exploiting atlassian and apache flaws Experts Warn of Ransomware Hackers Exploiting Atlassian and Apache Flaws
Next Post: Offensive and Defensive AI: Let’s Chat(GPT) About It offensive and defensive ai: let's chat(gpt) about it»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.