# SideCopy Expands Espionage Campaign to Indian Academia with ReverseRAT

*Published September 23, 2026*
*Source: [https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html](https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html)*

## Executive Summary

The cyber espionage group SideCopy has expanded its operations to target Indian academic institutions using spear-phishing and ReverseRAT malware. This move indicates a shift from their traditional focus on government entities to a broader set of targets.

## Article

The cyber threat group known as SideCopy has widened its scope to target Indian academic institutions through sophisticated spear-phishing techniques. Previously focused on Indian government and defense sectors, this Pakistani advanced persistent threat group has now shifted attention to academia, aiming to collect intelligence via its malware, ReverseRAT. According to Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C, SideCopy's operations begin with spear-phishing emails that exploit mshta.exe to deploy malicious scripts, effectively bypassing regular security measures.

This approach facilitates the installation of ReverseRAT, a remote access trojan that SideCopy has been using since 2021. The recent attack sequence involves delivering a compromised ZIP file that contains a Windows shortcut disguised as a legitimate document. Once activated, this shortcut retrieves an obfuscated HTML Application from a remote server and executes it with mshta.exe, which leads to the loading of a DLL payload. The malware employs a self-deleting routine to avoid forensic detection, removing traces of the initial file once its payload is deployed.

The DLL acts as a dropper for multiple components and executes a complex deobfuscation process to activate its payload in memory, making it difficult to detect through disk-based methods. ReverseRAT is capable of exfiltrating data, executing commands remotely, maintaining persistence, and more, all while encrypting its command-and-control traffic with a hard-coded key. Data is exfiltrated through an encrypted channel to a specific server.

This strategic shift by SideCopy demonstrates their evolving tactics and expanding priorities in intelligence gathering. With a focus on leveraging mshta.exe and advanced obfuscation, SideCopy remains a significant threat to regional cybersecurity efforts.
