The record
Written from the 1 report below. Nothing here is unsourced.
- The threat group known as SideCopy has expanded its operations to target academic institutions in India.
- Attackers use spear-phishing emails containing malicious LNK files that trigger remote script execution.
- The infection chain deploys a remote access trojan called ReverseRAT to exfiltrate sensitive data.
- This shift indicates a broader strategic focus for the group, which historically targeted government and defense entities.
What to watch next
- Future targeting of academic institutions by SideCopy
- Continued evolution of the group's mshta.exe abuse techniques
- Updates to the group's C2 infrastructure
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Boggavarapu R S S Srinivas Gupta
Trellix
1 quote · 1 outlet
“SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols”
In the article
…The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. " SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols ," Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C said in a technical report. "This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central…
Ravishankar N C
Trellix
1 quote · 1 outlet
“This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure.”
In the article
…that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C said in a technical report. " This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure. " Active since at least 2019, SideCopy (aka TAG-140) is an advanced persistent threat (APT) group that originates from Pakistan, and shares overlaps with the Transparent Tribe cluster. Historically, the threat actor has…
Coverage1
All filed from India
Named India · Afghanistan · Pakistan · Ministry of Finance · Boggavarapu R S S Srinivas Gupta · Ravishankar N C · ReverseRAT · Seqrite Labs · SideCopy · Transparent Tribe · Trellix
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
