NewsTradingSentimentEventsCommunityBriefing
Tech

SideCopy Targets Indian Universities with ReverseRAT

By Tech Desk · · 2 min read
A server rack in a dimly lit data center
Illustration: Tradingbird, based on a photo published by The Hacker News

A Pakistan-linked threat group has shifted focus from government bodies to academic institutions in India using sophisticated phishing techniques.

Key points

  • SideCopy targets Indian academic institutions using spear-phishing emails that disguise malware as legitimate documents.
  • The malware uses a remote access tool to steal data and operate in memory to avoid detection by security software.
  • This marks a strategic shift for the group, which previously focused primarily on government and defense targets in India.

A threat actor known as SideCopy is expanding its operations in India by targeting academic institutions, moving beyond its historical focus on government and defense entities. This shift signals a broader strategic interest in collecting intelligence from the education sector.

Researchers from Trellix documented this new campaign, which uses spear-phishing emails to deliver malicious software. The attacks rely on complex technical tricks to bypass standard security checks and install a remote access tool that allows attackers to control infected computers.

Phishing Disguises Malware As Documents

The attack begins with an email containing a ZIP file. Inside, a file named like a Word document is actually a Windows shortcut designed to look like a PDF. This trickery convinces users to open the file, thinking it is a legitimate document.

When opened, the file triggers a system tool to download and run hidden code from a remote server. This process loads a malicious component into the computer's memory. The system then deletes the initial file to make it harder for security tools to detect the intrusion.

Malware Operates Without Leaving Traces

The malware is designed to evade detection by staying in the computer's temporary memory rather than writing files to the hard drive. It uses a technique that decodes its core instructions directly in memory, making it difficult for standard antivirus software to find it.

Once active, the software installs a remote access tool called ReverseRAT. This tool allows attackers to steal passwords, take screenshots, and copy files from the clipboard. It also enables them to run commands on the computer as if they were sitting in front of it.

Strategic Shift Toward Academic Targets

SideCopy, also known as TAG-140, has been active since at least 2019. The group is believed to be based in Pakistan and has previously targeted Indian defense forces. The recent move toward universities suggests a change in their intelligence gathering priorities.

According to The Hacker News, this campaign highlights a disciplined approach to espionage. The attackers use encrypted communications to send stolen data to their servers, demonstrating a high level of technical sophistication. This poses a significant challenge for regional security teams trying to protect critical infrastructure.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories