Threats · 1 day ago
Trellix says SideCopy has broadened its spear-phishing campaign from Indian government targets to Indian academic institutions, using a ZIP lure and Windows shortcut to deliver ReverseRAT for collection and remote access. The group has been active since at least 2019 and is tracked as TAG-140.
The chain hides a malicious LNK file inside a ZIP, then uses it to fetch an obfuscated HTML Application and run it through Microsoft Windows mshta.exe, a built-in utility that can execute scripts. Parts of the payload are loaded into memory and a staging file is deleted, which leaves less on disk for file-based scanners to find while the RAT gathers data, passwords, clipboard content, and screenshots.
For schools and research institutes, the shift matters because the compromise can reach beyond one workstation: it can expose research material, staff or student credentials, and other accounts that support longer collection. The reporting leaves the same warning for defenders handling mail and endpoints in that sector: the lure format is simple, but the access path is built to evade routine disk checks.
1 source covering this story
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
SideCopy targets Indian academic institutions with spear-phishing that abuses mshta.exe to deploy ReverseRAT for collection and remote access.
Part of the PlainSec briefing for 2026-09-23