SideCopy Expands India Targeting to Academia With ReverseRAT Spear-Phishing
The SideCopy threat actor has been observed using spear-phishing lures against academic institutions in India, expanding beyond its usual government targets. Campaigns abuse mshta.exe to execute malicious scripts and evade standard security controls, delivering the ReverseRAT trojan.
- SideCopy shifted from Indian government targets to academic institutions
- Attacks begin with spear-phishing that abuses mshta.exe
- mshta.exe is used to bypass standard security protections
- The payload is the ReverseRAT remote access trojan
Read next
Security