Skip to content
SideCopy threat actor targets Indian academic institutions with new attack methods

SideCopy threat actor targets Indian academic institutions with new attack methods

Scworld September 23, 2026

The threat actor known as SideCopy has expanded its targeting to include academic institutions in India, shifting its focus from primarily government entities, The Hacker News reports.

SideCopy, an advanced persistent threat group originating from Pakistan and active since at least 2019, has historically targeted Indian defense forces and government officials. The latest observed campaign, detailed in a technical report by Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C, utilizes spear-phishing emails containing weaponized ZIP archives. These archives hold a Windows shortcut file (.lnk) disguised with a PDF icon and a .DOCX extension to appear legitimate. This LNK file executes a malicious HTML Application (HTA) using mshta.exe, which then loads a DLL payload. The malware employs an anti-forensic routine to delete the HTA file.

The DLL acts as a dropper for a batch script and a secondary exploit stage, which ultimately deploys the ReverseRAT remote access trojan. ReverseRAT is capable of collecting sensitive data, executing commands remotely, and maintaining persistence. Command-and-control traffic is encrypted, and data is exfiltrated to a specific IP address. This pivot to academic institutions suggests an expanding set of strategic priorities for the group.

Source: The Hacker News

SC Staff September 22, 2026

SC Staff September 22, 2026

SC Staff September 21, 2026

Get daily

You can skip this ad in 5 seconds

Extracted Entities

APT Groups (1)

Attack Types (2)

Countries (2)

Malware (1)

Platforms (1)

Tools (1)