Published: · Region: South Asia · Category: cyber

SideCopy hackers turn to Indian academia with stealthy ReverseRAT spear‑phishing chain

The SideCopy cyber‑espionage group is expanding from Indian government targets to universities and research institutions, using spear‑phishing that disguises a malicious Windows shortcut as a document and loads its ReverseRAT tool in memory for credential theft and data exfiltration.

A hacking group tracked as SideCopy is moving beyond Indian government targets and into the country’s academic sector, according to new research.

Security analysts say SideCopy is now going after universities and research institutions. Its latest spear‑phishing chain disguises a Windows shortcut (LNK) file as what appears to be a DOCX document. When victims open the file, it abuses the legitimate Windows component mshta.exe to pull in and run malicious code.

That code loads a remote‑access tool known as ReverseRAT directly into memory. By operating in memory, the malware can evade some traditional file‑based detection. Once active, ReverseRAT can collect credentials, execute commands on the victim system, maintain persistence and exfiltrate data.

Academia offers attackers a way into networks that hold valuable research and are often connected to government or industry partners but may not have the same level of security resources.

The technical breakdown published by researchers shows how SideCopy strings together file disguise, built‑in Windows utilities and in‑memory payloads to stay hidden while it gathers information.

Signs that this campaign is growing would include more incident reports from Indian universities linked to the same infrastructure and techniques, and evidence that similar spear‑phishing chains are being used against research institutions elsewhere.

Sources