[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fycUCdXDvoHp5TVBY9WMeHyR8lY1HQA27X0-I-_xsq20":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"b73461dc-23db-45b4-a037-63ae6ae4457a","SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing","sidecopy-broadens-india-targeting-to-academia-with-reverserat-spear-phishing-c8f864","The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. \"SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,\" Trellix researchers","The Pakistan-based APT group SideCopy, also known as TAG-140, has expanded its targeting in India to include academic institutions, moving beyond its historical focus on government entities. The group employs spear-phishing campaigns that abuse mshta.exe to deliver its ReverseRAT malware, which is capable of extensive data exfiltration and remote control.","SideCopy APT group targets Indian academia with ReverseRAT via spear-phishing.","SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing Ravie LakshmananSep 22, 2026Malware \u002F Cyber Espionage The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. \"SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,\" Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C said in a technical report. \"This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure.\" Active since at least 2019, SideCopy (aka TAG-140) is an advanced persistent threat (APT) group that originates from Pakistan, and shares overlaps with the Transparent Tribe cluster. Historically, the threat actor has primarily targeted Indian defense forces and government officials. In a report published in June 2026, Seqrite Labs attributed SideCopy to a spear-phishing campaign targeting Afghanistan's Ministry of Finance with an open-source remote access trojan called Xeno RAT. The latest attack chain documented by Trellix uses spear-phishing to deliver a weaponized ZIP archive, within which exists a Windows shortcut (LNK) with a spoofed PDF icon and a .DOCX extension (\"commskll.docx.lnk\") to make the malicious file look legitimate. The LNK file is used to fetch an obfuscated HTML Application (HTA) from a remote server (\"docsportal[.]in\") and execute it using \"mshta.exe,\" which then proceeds to reflectively load a DLL payload. The malware makes use of an anti-forensic self-deletion routine that deletes the HTA file once the subsequent stage is initialized. The DLL serves as a dropper for three embedded components - appT.bat, a batch script that's launched by means of a Windows Registry Run Key to execute \"startT.hta\" using \"mshta.exe\" without requiring user interaction startT.hta, a secondary exploit stage that contains the obfuscated final payload commskl.docx, a decoy document \"The obfuscated code within startT.hta executes a multi-stage deobfuscation routine to reconstruct a two-part XAML payload directly in memory,\" Trellix explained, adding it's responsible for reflectively loading an embedded DLL (\"ioluegnt.dll\"). \"To evade disk-based detection, the malware decodes its core payload into volatile memory space, transitioning from a Base64-encoded string to an active, in-memory process via .NET Deserialization.\" The DLL is a remote access trojan named ReverseRAT, which has been put to use by SideCopy since early 2021 to facilitate data exfiltration, remote execution, and persistence. It's equipped to gather system metadata, a list of installed software, screenshots, passwords, and clipboard content; perform file operations; run commands; set up persistence via Registry; upload files; and spawn a shell session. The command-and-control (C2) traffic is encrypted using a hard-coded cryptographic key (\"NMXIKS09?:709,!~lnsYUS\"). The harvested data is exfiltrated via port 5863 to \"dns.educationportals[.]biz,\" which resolves to the IP address \"45.61.157[.]22.\" \"The current activities of SideCopy underscore a disciplined and highly strategic approach to intelligence collection,\" Trellix concluded. \"While their historical focus has been on Indian government entities, their recent pivot toward academic institutions highlights an expanding set of strategic priorities.\" \"By continuously refining their infection stages, most notably through the heavy abuse of mshta.exe and complex, multilayered obfuscation, they remain a formidable and adaptive adversary for regional security.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cyber espionage, Malware, Phishing, Windows Security ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fsidecopy-broadens-india-targeting-to.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgVXTuBFDgZyaNFTznwdu5HXSKuVHU5xpM7JDvXP_Ra-68CsYd68bb6xMWPXbjmsM5oO211hZgzIN0NENk_cMBZZpL88LMsIaNkfSEpIWRRzyjRt7Ke6ZMeUXvIKcH3ncgDouKN8FGuunAFQFMolel0GgTBm1lzdVDH28WpWFUCI4Fvl9ju0q4Vv0S55PVx\u002Fs1600\u002Fword-school.jpg","2026-09-22T07:52:03+00:00","2026-09-22T10:00:20.142049+00:00",8,[18,21,23,25],{"name":19,"type":20},"SideCopy","threat_actor",{"name":22,"type":20},"TAG-140",{"name":24,"type":20},"Transparent Tribe",{"name":26,"type":27},"Trellix","vendor","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":28,"icon":30,"name":31,"slug":32},null,"Nation-state","nation-state",[34,39,41,46],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":40},{"id":28,"icon":30,"name":31,"slug":32},{"category":42},{"id":43,"icon":30,"name":44,"slug":45},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":47},{"id":48,"icon":30,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,56,59,63,66,69,73,76,79,82,85,88,91,94,97,100,103,106,109],{"type":53,"value":54,"context":55},"domain","docsportal[.]in","Malicious domain used to host HTA payload.",{"type":53,"value":57,"context":58},"dns.educationportals[.]biz","Command and control (C2) domain for data exfiltration.",{"type":60,"value":61,"context":62},"ip","45.61.157[.]22","IP address associated with the C2 domain dns.educationportals[.]biz.",{"type":45,"value":64,"context":65},"ReverseRAT","Remote Access Trojan (RAT) used by SideCopy.",{"type":45,"value":67,"context":68},"Xeno RAT","Open-source RAT previously attributed to SideCopy.",{"type":70,"value":71,"context":72},"mitre_attack","T1059.003","Abuse of mshta.exe for script execution.",{"type":70,"value":74,"context":75},"T1566.002","Spear-phishing attachment.",{"type":70,"value":77,"context":78},"T1071.001","Web protocols for C2 communication.",{"type":70,"value":80,"context":81},"T1041","Exfiltration over C2 channel.",{"type":70,"value":83,"context":84},"T1027","Obfuscated files or information.",{"type":70,"value":86,"context":87},"T1140","Deobfuscate\u002Fdecode files or information.",{"type":70,"value":89,"context":90},"T1053.005","Scheduled task\u002Ftimer.",{"type":70,"value":92,"context":93},"T1553.005","Mark-of-the-Web bypass.",{"type":70,"value":95,"context":96},"T1003","OS credential dumping.",{"type":70,"value":98,"context":99},"T1113","Screen capture.",{"type":70,"value":101,"context":102},"T1115","Clipboard data.",{"type":70,"value":104,"context":105},"T1083","File and directory discovery.",{"type":70,"value":107,"context":108},"T1082","System information discovery.",{"type":70,"value":110,"context":111},"T1547.001","Registry Run Keys \u002F Startup Folder."]