Threats & Adversaries · APT / Espionage

SideCopy Shifts Espionage Lures Toward Indian Academia

Trellix says SideCopy has broadened its spear-phishing campaign from Indian government targets to Indian academic institutions, using a ZIP lure and Windows shortcut to deliver ReverseRAT for collection and remote access. The group has been active since at least 2019 and is tracked as TAG-140.

The chain hides a malicious LNK file inside a ZIP, then uses it to fetch an obfuscated HTML Application and run it through Microsoft Windows mshta.exe, a built-in utility that can execute scripts. Parts of the payload are loaded into memory and a staging file is deleted, which leaves less on disk for file-based scanners to find while the RAT gathers data, passwords, clipboard content, and screenshots.

For schools and research institutes, the shift matters because the compromise can reach beyond one workstation: it can expose research material, staff or student credentials, and other accounts that support longer collection. The reporting leaves the same warning for defenders handling mail and endpoints in that sector: the lure format is simple, but the access path is built to evade routine disk checks.

1 source · Sep 22

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-22

Every edition of this story: SideCopy Shifts Espionage Lures Toward Indian Academia

More from today