SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

LowThe Hacker News · info@thehackernews.com (The Hacker News)·

At a glance

Severity
Low
Used in attacks
No flaws named
Industries
Government
Reported by
1 outlet

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.

"SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C said in a technical report.

"This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure."

Active since at least 2019, SideCopy (aka TAG-140) is an advanced persistent threat (APT) group that originates from Pakistan, and shares overlaps with the Transparent Tribe cluster. Historically, the threat actor has primarily targeted Indian defense forces and government officials.

In a report published in June 2026, Seqrite Labs attributed SideCopy to a spear-phishing campaign targeting Afghanistan's Ministry of Finance with an open-source remote access trojan called Xeno RAT.

The latest attack chain documented by Trellix uses spear-phishing to deliver a weaponized ZIP archive, within which exists a Windows shortcut (LNK) with a spoofed PDF icon and a .DOCX extension ("commskll.docx.lnk") to make the malicious file look legitimate.

The LNK file is used to fetch an obfuscated HTML Application (HTA) from a remote server ("docsportal[.]in") and execute it using "mshta.exe," which then proceeds to reflectively load a DLL payload. The malware makes use of an anti-forensic self-deletion routine that deletes the HTA file once the subsequent stage is initialized.

The DLL serves as a dropper for three embedded components -

  • appT.bat, a batch script that's launched by means of a Windows Registry Run Key to execute "startT.hta" using "mshta.exe" without requiring user interaction
  • startT.hta, a secondary exploit stage that contains the obfuscated final payload
  • commskl.docx, a decoy document

"The obfuscated code within startT.hta executes a multi-stage deobfuscation routine to reconstruct a two-part XAML payload directly in memory," Trellix explained, adding it's responsible for reflectively loading an embedded DLL ("ioluegnt.dll").

"To evade disk-based detection, the malware decodes its core payload into volatile memory space, transitioning from a Base64-encoded string to an active, in-memory process via .NET Deserialization."

The DLL is a remote access trojan named ReverseRAT, which has been put to use by SideCopy since early 2021 to facilitate data exfiltration, remote execution, and persistence. It's equipped to gather system metadata, a list of installed software, screenshots, passwords, and clipboard content; perform file operations; run commands; set up persistence via Registry; upload files; and spawn a shell session.

The command-and-control (C2) traffic is encrypted using a hard-coded cryptographic key ("NMXIKS09?:709,!~lnsYUS"). The harvested data is exfiltrated via port 5863 to "dns.educationportals[.]biz," which resolves to the IP address "45.61.157[.]22."

"The current activities of SideCopy underscore a disciplined and highly strategic approach to intelligence collection," Trellix concluded. "While their historical focus has been on Indian government entities, their recent pivot toward academic institutions highlights an expanding set of strategic priorities."

"By continuously refining their infection stages, most notably through the heavy abuse of mshta.exe and complex, multilayered obfuscation, they remain a formidable and adaptive adversary for regional security."

Reproduced in full under licence from The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).

Coverage

One outlet has carried this so far.

  1. The Hacker NewsEstablished SourceFirst reported

    2026-09-22 07:52 UTC

Related stories