SideCopy APT Targets Indian Academia with Spear-Phishing and ReverseRAT
The Pakistan-linked APT group SideCopy has expanded its spear-phishing campaigns beyond Indian government targets to now include academic institutions, exploiting the often-weaker security postures found in educational environments. The attacks abuse mshta.exe, a legitimate Windows binary, to execute malicious HTA files delivered via convincing phishing lures — a technique known as 'living off the land' that bypasses many traditional defenses. Once ReverseRAT is deployed, attackers gain persistent remote access and can exfiltrate sensitive research, credentials, and institutional data. This expansion highlights how APT groups deliberately pivot to softer targets within a nation's critical ecosystem when primary targets harden their defenses.
Tactical Insight
Immediate Actions
- Block or heavily restrict execution of mshta.exe via application control policies (e.g., Windows Defender Application Control or AppLocker) on all endpoints.
- Deploy anti-phishing email filtering with sandboxing to inspect and detonate suspicious attachments and links before delivery.
- Conduct emergency phishing simulation exercises targeting academic staff and students to assess current susceptibility levels.
Long-Term Improvements
- Establish a mandatory, role-based security awareness training program for all faculty, staff, and students covering spear-phishing recognition.
- Implement network segmentation to isolate research systems, administrative networks, and student environments from one another.
- Develop and rehearse an incident response plan specifically tailored to APT intrusion scenarios, including ReverseRAT indicators of compromise.
Detection Measures
- Enable and centralize logging of mshta.exe process execution events and alert on anomalous parent-child process relationships via a SIEM platform.
- Deploy endpoint detection and response (EDR) solutions capable of identifying living-off-the-land binary (LOLBin) abuse in real time.
- Subscribe to threat intelligence feeds covering SideCopy/TAG-140 TTPs and integrate IOCs into perimeter and endpoint defenses.