importantSYS.SOURCE: The Hacker News• 2026-09-22T13:22:03+05:30
SideCopy APT Group Expands Targeting of Indian Academia via ReverseRAT Spear-Phishing
SideCopy, a Pakistani APT group, has expanded its targeting to Indian academic institutions through spear-phishing campaigns delivering ReverseRAT malware. The attack uses obfuscated scripts and mshta.exe to execute multi-stage payloads, enabling data exfiltration and system compromise.
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.
"SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers
*** END OF TRANSMISSION ***