Hackers (SideCopy), allegedly linked to Pakistan, are targeting various domains in trojans remote access such as Xeno RAT, Spark RAT, and the new CurlBack RAT.

The activity, detected by SEQRITE in December 2024, targeted Indian entities under the ministries of railways, oil and gas, and external affairs. Until now, hackers have mainly targeted government, defense, and shipping agencies, as well as universities.
"A notable change in recent campaigns is the shift from using HTML Application (HTA) files to adopting Microsoft Installer (MSI) packages as the primary staging mechanism," said security researcher Sathwik Ram Prakki.
See also: GitHub's new Sakura RAT evades AV & EDR protections
The SideCopy group is considered a sub-cluster of Transparent Tribe (also known as APT36) that has been active since at least 2019. It was named SideCopy because it appears to mimic the attack chains of another group called SideWinder.
In June 2024, SEQRITE reported that SideCopy hackers were using HTA files, leveraging techniques previously observed in SideWinder attacks. It was also found that the files contained references to URLs hosting RTF files, which had also been used by SideWinder.
The attacks led to the development of Action RAT and ReverseRAT, two malware attributed to SideCopy. Several other payloads have also been identified, including Cheex for stealing documents and images, a USB copier for collecting data from attached drives, and the Geta RAT that can execute 30 commands sent from a remote server.
The RAT is equipped to steal data from browsers (Firefox and Chromium) accounts, profiles, and cookies.
“APT36’s focus is primarily on Linux systems, while SideCopy targets Windows by adding new payloads to its arsenal,” SEQRITE said at the time.
See also: SnowDog: New RAT malware advertised on hacking forums
The latest findings demonstrate a continued maturation of the hacking group, which is leveraging phishing emails as a distribution vehicle for malware. The emails contain various documents as bait, ranging from holiday/leave lists for railway staff to cybersecurity guidelines issued by a public sector undertaking called Hindustan Petroleum Corporation Limited (HPCL).
The latest attacks ultimately lead to the development of the Spark RAT and a new Windows malware codenamed CurlBack RAT. CurlBack can collect system information, download files from the host computer, execute arbitrary commands, escalate privileges, and log user accounts.

Protection against RAT malware
The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.
Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect computer from the latest known trojans.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Russian hackers Gamaredon target Ukraine with Remcos RAT
You should also be careful with emails and messages you receive. Many RAT malware are spread through phishing attacks, so avoid opening attachments or clicking links from unknown sources.
Using strong passwords and changing them regularly can also help protect against attacks . Using two-factor authentication can also add an extra layer of security.
Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.
Source: thehackernews.com
