EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 85/100

SideCopy, un gruppo APT originario del Pakistan, ha esteso il suo targeting in India verso istituti accademici tramite spear-phishing. L'attacco utilizza mshta.exe per eseguire script malevoli e scaricare ReverseRAT, un RAT che permette accesso remoto, esfiltrazione dati e persistenza. Il malware si autoelimina per evitare la rilevazione. La C2 usa un IP risolto da dns.educationportals.biz. La patch non è indicata.

Why it matters

Per le PMI italiane, il rischio è la compromissione di dati sensibili e la perdita di controllo su sistemi critici. L'espansione del targeting a istituti accademici potrebbe compromettere la ricerca e la sicurezza informatica di settori chiave.

Potential operational benefits

  • Riduzione della superficie esposta
  • Miglioramento della rilevazione in tempo reale
  • Prevenzione di accessi non autorizzati
  • Riduzione del rischio di esfiltrazione dati
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsFirewall NGFW / IPSEDR / XDRPatch managementMonitoraggio / SIEMSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
22/09/2026 09:52
MITRE ATT&CK
T1190, T1078, T1486
Open the original source