CSIDB logo
Threat actor

STEPPY#KAVACH

Attribution profile

Type
Spy
Location
Pakistan
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-31 02:38
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

STEPPY#KAVACH is the alias used by Securonix Threat Labs to track a malicious threat actor that has been observed targeting individuals associated with the Indian government. The actor’s location is noted as Pakistan in the provided context, and some researchers have previously linked similar activity to Pakistani‑based groups such as SideCopy, APT36 and TransparentTribe. The actor’s activity has been described as a new campaign that shares many tactics, techniques and procedures with those earlier groups, particularly in the use of phishing shortcuts and living‑off‑the‑land binaries to deliver a custom remote access tool.

The infection chain typically begins with a phishing email that contains a compressed attachment holding a shortcut file named Scanimg.png.lnk. When opened, the shortcut invokes mshta.exe to retrieve a remote HTML application (HTA) file hosted on a compromised website under the path incometaxdelhi[.]org/gallery/thumnails/mix/sit.hta. The HTA file contains obfuscated JavaScript that first checks for the presence of .NET Framework v4.0.30319 and then proceeds through a series of JScript files. These scripts perform functions such as downloading a decoy image (8292.png) via PowerShell’s Invoke‑WebRequest, creating a directory under C:\ProgramData\dvixm, downloading a binary payload (mm1.exe) from the IP address 155.133.23.244/d.php, establishing persistence by writing a registry value under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run that points to C:\ProgramData\dvixm\dvimo.exe, and finally triggering a system reboot. The payload itself is a C#‑written remote access trojan that employs Triple‑DES in ECB mode to encrypt its command‑and‑control traffic, and it leverages additional capabilities such as executing remote VBScript files and using standard Windows utilities like mshta.exe as a living‑off‑the‑land binary to avoid detection.

The campaign analyzed by Securonix in December 2022 exemplifies the actor’s recent activity, demonstrating a clear focus on Indian government employees through lure documents that referenced outdated news articles from PIB Delhi. The observed overlaps with SideCopy/APT36/TransparentTribe—particularly in the use of .LNK‑initiated mshta.exe chains, JScript‑based staging, registry‑based persistence, and Triple‑DES encrypted C2—have been noted by researchers who attribute those earlier clusters to Pakistan. While the text does not specify the actor’s ultimate objectives, the repeated targeting of governmental entities and the use of espionage‑oriented techniques such as credential harvesting, persistence mechanisms and encrypted communications are consistent with the patterns described in the referenced reporting. This summary reflects only the information explicitly provided in the source material.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB