Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SideCopy Shifts Focus to Indian Academia with ReverseRAT

SideCopy Shifts Focus to Indian Academia with ReverseRAT

Posted on September 22, 2026 By CWS

SideCopy, a known cyber-espionage group, has expanded its operations to target academic institutions in India. Previously focused on government agencies, this Pakistani-origin group is now employing spear-phishing tactics against educational entities, according to a report by Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C.

Spear-Phishing Techniques and Malware Deployment

SideCopy’s campaigns begin with spear-phishing emails that exploit mshta.exe to run harmful scripts, bypassing typical security measures. This method allows for the deployment of a remote access trojan (RAT), a key component of the group’s attack strategy. Operating since at least 2019, SideCopy shares connections with the Transparent Tribe cluster and has historically focused on Indian defense and governmental targets.

In June 2026, Seqrite Labs linked SideCopy to a spear-phishing attack on Afghanistan’s Ministry of Finance using Xeno RAT, an open-source malware. Their latest strategy involves sending weaponized ZIP files containing LNK files disguised as PDFs to execute malicious code when opened.

Advanced Attack Chain and Obfuscation

The attack chain includes fetching an obfuscated HTML Application from a remote server, executed via mshta.exe. Once activated, this application loads a DLL payload, which is crucial for the attack’s success. The malware employs anti-forensic measures, deleting files to cover its tracks after execution begins.

Three components, including a batch script and a decoy document, are deployed to maintain persistence without user involvement. The malware’s obfuscated code reconstructs a XAML payload in memory, bypassing disk-based detection through complex deobfuscation and .NET Deserialization techniques.

ReverseRAT and Data Exfiltration

ReverseRAT, used by SideCopy since 2021, facilitates various malicious activities such as data exfiltration, remote command execution, and system persistence. It collects system data, software information, screenshots, passwords, and more while maintaining a low profile.

Communication with command-and-control servers occurs through encrypted traffic using a specific cryptographic key. Data is sent to a server via a designated port, illustrating the group’s sophisticated approach to intelligence gathering.

The recent targeting of academic institutions by SideCopy signals a broadening of their operational scope. This shift in focus highlights their strategic evolution and adaptability, posing new challenges for cybersecurity efforts in the region.

By refining their attack methodologies and employing sophisticated obfuscation techniques, SideCopy remains a persistent threat to regional security, emphasizing the need for heightened vigilance and improved defensive measures.

The Hacker News Tags:academic institutions, APT group, cyber espionage, Cybersecurity, data exfiltration, Indian academia, Malware, mshta.exe, remote access trojan, ReverseRAT, Seqrite Labs, SideCopy, spear-phishing, Transparent Tribe, Trellix

Post navigation

Previous Post: WordPress Patch Fixes Critical Comment2Shell Vulnerability
Next Post: Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme

Related Posts

CISOs Tackle Burnout and Reduce MTTR Without Extra Staff CISOs Tackle Burnout and Reduce MTTR Without Extra Staff The Hacker News
State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks The Hacker News
Gitea Vulnerability Allows File Access Without Authentication Gitea Vulnerability Allows File Access Without Authentication The Hacker News
Critical Cisco SD-WAN Vulnerability Exploited Since 2023 Critical Cisco SD-WAN Vulnerability Exploited Since 2023 The Hacker News
Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems The Hacker News
FortiGate Firewalls Exploited by Cyber Attackers FortiGate Firewalls Exploited by Cyber Attackers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
  • SideCopy Shifts Focus to Indian Academia with ReverseRAT
  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
  • SideCopy Shifts Focus to Indian Academia with ReverseRAT
  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark