Back Scworld SideCopy threat actor targets Indian academic institutions with new attack methods
The threat actor known as SideCopy has expanded its targeting to include academic institutions in India, shifting its focus from primarily government entities, The Hacker News reports.
SideCopy, an advanced persistent threat group originating from Pakistan and active since at least 2019, has historically targeted Indian defense forces and government officials. The latest observed campaign, detailed in a technical report by Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C, utilizes spear-phishing emails containing weaponized ZIP archives. These archives hold a Windows shortcut file (.lnk) disguised with a PDF icon and a .DOCX extension to appear legitimate. This LNK file executes a malicious HTML Application (HTA) using mshta.exe, which then loads a DLL payload. The malware employs an anti-forensic routine to delete the HTA file.
The DLL acts as a dropper for a batch script and a secondary exploit stage, which ultimately deploys the ReverseRAT remote access trojan. ReverseRAT is capable of collecting sensitive data, executing commands remotely, and maintaining persistence. Command-and-control traffic is encrypted, and data is exfiltrated to a specific IP address. This pivot to academic institutions suggests an expanding set of strategic priorities for the group.
Source: The Hacker News
SC Staff September 22, 2026
SC Staff September 22, 2026
SC Staff September 21, 2026
Get daily
You can skip this ad in 5 seconds
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
