By Interestana AI Editorial — AI-drafted, human-overseen. How we report
SideCopy Expands India Targeting to Academia Using ReverseRAT via Spear-Phishing

The sophisticated threat actor known as SideCopy has significantly broadened its operational focus within India, extending its spear-phishing campaigns to target academic institutions. This strategic expansion marks a notable shift from SideCopy's previously observed primary focus on government entities. The intelligence comes from researchers at Trellix, a global leader in cybersecurity, who have been meticulously tracking the group's activities. Trellix's analysis indicates that SideCopy's campaign operations consistently initiate through meticulously crafted spear-phishing attacks. These attacks are designed to exploit human vulnerabilities and circumvent standard security protocols, making them a persistent threat.
A key technique employed by SideCopy involves the abuse of the legitimate Microsoft Windows utility, `mshta.exe` (Microsoft HTML Application host). This utility is designed to execute HTML applications, but SideCopy leverages it to run malicious scripts. By using a trusted Windows component, the threat actor can often bypass security software that might otherwise flag or block standalone malicious executables. This method lends a veneer of legitimacy to the execution process, making it more challenging for security systems and end-users to discern malicious activity from benign operations.
Central to these attacks is the deployment of ReverseRAT, a potent remote access trojan (RAT) frequently associated with SideCopy's operations. Once successfully installed on a victim's system, ReverseRAT grants SideCopy operators extensive remote control. This allows them to conduct in-depth reconnaissance of the compromised network, identify valuable data, exfiltrate sensitive information, and potentially deploy further malicious payloads to escalate their attack. While the specific types of data being targeted from academic institutions are still under investigation, such organizations are known to house a wealth of high-value assets. These include cutting-edge research findings, proprietary intellectual property, and the personal data of students and faculty, all of which can be exploited for espionage, financial gain, or further malicious purposes.
SideCopy has been an active threat actor for several years, demonstrating a pattern of persistent and evolving tactics, techniques, and procedures (TTPs). Their continuous refinement of attack methods and diversification of targets, such as the recent move into the academic sector in India, highlight a strategic approach to identifying and exploiting high-value targets. This development underscores the critical need for enhanced cybersecurity defenses within educational institutions, which may not always possess the same robust security infrastructure or resources as government agencies or large commercial enterprises. Trellix's ongoing threat intelligence efforts are crucial in providing visibility into these sophisticated attacks and informing adaptive security strategies necessary to counter actors like SideCopy.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.