SideCopy, a known cyber-espionage group, has expanded its operations to target academic institutions in India. Previously focused on government agencies, this Pakistani-origin group is now employing spear-phishing tactics against educational entities, according to a report by Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C.
Spear-Phishing Techniques and Malware Deployment
SideCopy’s campaigns begin with spear-phishing emails that exploit mshta.exe to run harmful scripts, bypassing typical security measures. This method allows for the deployment of a remote access trojan (RAT), a key component of the group’s attack strategy. Operating since at least 2019, SideCopy shares connections with the Transparent Tribe cluster and has historically focused on Indian defense and governmental targets.
In June 2026, Seqrite Labs linked SideCopy to a spear-phishing attack on Afghanistan’s Ministry of Finance using Xeno RAT, an open-source malware. Their latest strategy involves sending weaponized ZIP files containing LNK files disguised as PDFs to execute malicious code when opened.
Advanced Attack Chain and Obfuscation
The attack chain includes fetching an obfuscated HTML Application from a remote server, executed via mshta.exe. Once activated, this application loads a DLL payload, which is crucial for the attack’s success. The malware employs anti-forensic measures, deleting files to cover its tracks after execution begins.
Three components, including a batch script and a decoy document, are deployed to maintain persistence without user involvement. The malware’s obfuscated code reconstructs a XAML payload in memory, bypassing disk-based detection through complex deobfuscation and .NET Deserialization techniques.
ReverseRAT and Data Exfiltration
ReverseRAT, used by SideCopy since 2021, facilitates various malicious activities such as data exfiltration, remote command execution, and system persistence. It collects system data, software information, screenshots, passwords, and more while maintaining a low profile.
Communication with command-and-control servers occurs through encrypted traffic using a specific cryptographic key. Data is sent to a server via a designated port, illustrating the group’s sophisticated approach to intelligence gathering.
The recent targeting of academic institutions by SideCopy signals a broadening of their operational scope. This shift in focus highlights their strategic evolution and adaptability, posing new challenges for cybersecurity efforts in the region.
By refining their attack methodologies and employing sophisticated obfuscation techniques, SideCopy remains a persistent threat to regional security, emphasizing the need for heightened vigilance and improved defensive measures.
