{"id":3049,"date":"2026-09-22T09:53:22","date_gmt":"2026-09-22T09:53:22","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3049"},"modified":"2026-09-22T09:53:22","modified_gmt":"2026-09-22T09:53:22","slug":"sidecopy-broadens-india-targeting-to-academia-with-reverserat-spear-phishing","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3049","title":{"rendered":"SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 22, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cyber Espionage<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgVXTuBFDgZyaNFTznwdu5HXSKuVHU5xpM7JDvXP_Ra-68CsYd68bb6xMWPXbjmsM5oO211hZgzIN0NENk_cMBZZpL88LMsIaNkfSEpIWRRzyjRt7Ke6ZMeUXvIKcH3ncgDouKN8FGuunAFQFMolel0GgTBm1lzdVDH28WpWFUCI4Fvl9ju0q4Vv0S55PVx\/s1700-nu-rw-lo-l85-e365\/word-school.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The threat actor known as <strong>SideCopy<\/strong> has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.<\/p>\n<p>\u00abSideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,\u00bb Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C <a href=\"https:\/\/www.trellix.com\/blogs\/research\/sidecopy-threat-intel-mshta-execution-rat-deployment\/\" target=\"_blank\">said<\/a> in a technical report.<\/p>\n<p>\u00abThis delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure.\u00bb<\/p>\n<p>Active since at least 2019, <a href=\"https:\/\/cyble.com\/threat-actor-profiles\/sidecopy\/\" target=\"_blank\">SideCopy<\/a> (aka TAG-140) is an advanced persistent threat (APT) group that originates from Pakistan, and shares overlaps with the Transparent Tribe cluster. Historically, the threat actor has primarily targeted Indian defense forces and government officials.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In a report published in June 2026, Seqrite Labs attributed SideCopy to a spear-phishing campaign targeting Afghanistan&#8217;s Ministry of Finance with an open-source remote access trojan called Xeno RAT.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The latest attack chain documented by Trellix uses spear-phishing to deliver a weaponized ZIP archive, within which exists a Windows shortcut (LNK) with a spoofed PDF icon and a .DOCX extension (\u00abcommskll.docx.lnk\u00bb) to make the malicious file look legitimate.<\/p>\n<p>The LNK file is used to fetch an obfuscated HTML Application (HTA) from a remote server (\u00abdocsportal[.]in\u00bb) and execute it using \u00abmshta.exe,\u00bb which then proceeds to reflectively load a DLL payload. The malware makes use of an anti-forensic self-deletion routine that deletes the HTA file once the subsequent stage is initialized.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh9mfDAw7FmjS5ZKa8qAf1NexMEUtbf8eE_8FRNutRU_GSrgEhKbN8Knoxg3Om845RRP1S1BMtqBW3rfXtxCfB_ebOowlsrDCXluuWkXU05L6YRih-8b3Zb1JTgK-e-QaFg6sjLQDoTGD3cuDHerOucnjPZ5A4ciyAzneJBCcIQO-HF6j84OLwbL49RpffV\/s1700-nu-rw-lo-l85-e365\/side.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh9mfDAw7FmjS5ZKa8qAf1NexMEUtbf8eE_8FRNutRU_GSrgEhKbN8Knoxg3Om845RRP1S1BMtqBW3rfXtxCfB_ebOowlsrDCXluuWkXU05L6YRih-8b3Zb1JTgK-e-QaFg6sjLQDoTGD3cuDHerOucnjPZ5A4ciyAzneJBCcIQO-HF6j84OLwbL49RpffV\/s1700-nu-rw-lo-l85-e365\/side.jpg\" alt=\"\" border=\"0\" data-original-height=\"862\" data-original-width=\"787\"\/><\/a><\/div>\n<p>The DLL serves as a dropper for three embedded components &#8211;<\/p>\n<ul>\n<li>appT.bat, a batch script that&#8217;s launched by means of a Windows Registry Run Key to execute \u00abstartT.hta\u00bb using \u00abmshta.exe\u00bb without requiring user interaction<\/li>\n<li>startT.hta, a secondary exploit stage that contains the obfuscated final payload<\/li>\n<li>commskl.docx, a decoy document<\/li>\n<\/ul>\n<p>\u00abThe obfuscated code within startT.hta executes a multi-stage deobfuscation routine to reconstruct a two-part XAML payload directly in memory,\u00bb Trellix explained, adding it&#8217;s responsible for reflectively loading an embedded DLL (\u00abioluegnt.dll\u00bb).<\/p>\n<p>\u00abTo evade disk-based detection, the malware decodes its core payload into volatile memory space, transitioning from a Base64-encoded string to an active, in-memory process via .NET Deserialization.\u00bb<\/p>\n<p>The DLL is a remote access trojan named ReverseRAT, which has been put to use by SideCopy since early 2021 to facilitate data exfiltration, remote execution, and persistence. It&#8217;s equipped to gather system metadata, a list of installed software, screenshots, passwords, and clipboard content; perform file operations; run commands; set up persistence via Registry; upload files; and spawn a shell session.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The command-and-control (C2) traffic is encrypted using a hard-coded cryptographic key (\u00abNMXIKS09?:709,!~lnsYUS\u00bb). The harvested data is exfiltrated via port 5863 to \u00abdns.educationportals[.]biz,\u00bb which resolves to the IP address \u00ab45.61.157[.]22.\u00bb<\/p>\n<p>\u00abThe current activities of SideCopy underscore a disciplined and highly strategic approach to intelligence collection,\u00bb Trellix concluded. \u00abWhile their historical focus has been on Indian government entities, their recent pivot toward academic institutions highlights an expanding set of strategic priorities.\u00bb<\/p>\n<p>\u00abBy continuously refining their infection stages, most notably through the heavy abuse of mshta.exe and complex, multilayered obfuscation, they remain a formidable and adaptive adversary for regional security.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 22, 2026Malware \/ Cyber Espionage The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3050,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3494,3493,503,3495,1862,947,431],"class_list":["post-3049","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-academia","tag-broadens","tag-india","tag-reverserat","tag-sidecopy","tag-spearphishing","tag-targeting"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3049"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3049\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3050"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}