SideCopy Targets Indian Universities with ReverseRAT

A Pakistan-linked threat group has shifted focus from government bodies to academic institutions in India using sophisticated phishing techniques.
Key points
- SideCopy targets Indian academic institutions using spear-phishing emails that disguise malware as legitimate documents.
- The malware uses a remote access tool to steal data and operate in memory to avoid detection by security software.
- This marks a strategic shift for the group, which previously focused primarily on government and defense targets in India.
A threat actor known as SideCopy is expanding its operations in India by targeting academic institutions, moving beyond its historical focus on government and defense entities. This shift signals a broader strategic interest in collecting intelligence from the education sector.
Researchers from Trellix documented this new campaign, which uses spear-phishing emails to deliver malicious software. The attacks rely on complex technical tricks to bypass standard security checks and install a remote access tool that allows attackers to control infected computers.
Phishing Disguises Malware As Documents
The attack begins with an email containing a ZIP file. Inside, a file named like a Word document is actually a Windows shortcut designed to look like a PDF. This trickery convinces users to open the file, thinking it is a legitimate document.
When opened, the file triggers a system tool to download and run hidden code from a remote server. This process loads a malicious component into the computer's memory. The system then deletes the initial file to make it harder for security tools to detect the intrusion.
Malware Operates Without Leaving Traces
The malware is designed to evade detection by staying in the computer's temporary memory rather than writing files to the hard drive. It uses a technique that decodes its core instructions directly in memory, making it difficult for standard antivirus software to find it.
Once active, the software installs a remote access tool called ReverseRAT. This tool allows attackers to steal passwords, take screenshots, and copy files from the clipboard. It also enables them to run commands on the computer as if they were sitting in front of it.
Strategic Shift Toward Academic Targets
SideCopy, also known as TAG-140, has been active since at least 2019. The group is believed to be based in Pakistan and has previously targeted Indian defense forces. The recent move toward universities suggests a change in their intelligence gathering priorities.
According to The Hacker News, this campaign highlights a disciplined approach to espionage. The attackers use encrypted communications to send stolen data to their servers, demonstrating a high level of technical sophistication. This poses a significant challenge for regional security teams trying to protect critical infrastructure.






