#ParsedReport #CompletenessHigh
17-09-2026
SideCopy Threat Intel: MSHTA-driven Execution and RAT Deployment
https://www.trellix.com/blogs/research/sidecopy-threat-intel-mshta-execution-rat-deployment/
Report completeness: High
Actors/Campaigns:
Sidecopy
Threats:
Spear-phishing_technique
Lolbin_technique
Reverserat_rat
Heracles
Trojan.js.generic.mvx
Lolbas_technique
Victims:
Government, Academic institutions, Government officials, High ranking personnel
Industry:
Government
Geo:
Indian
TTPs:
Tactics: 5
Technics: 9
IOCs:
File: 11
Domain: 2
IP: 1
Hash: 7
Url: 3
Soft:
Windows Registry, Linux, Android
Algorithms:
aes, gzip, zip, base64
Functions:
SetCurPos, GetHostsFile, GetCPText
Win API:
ARC
Languages:
powershell
Platforms:
intel
Post #32621
96