The Pakistani threat actor SideCopy has expanded its spear-phishing operations to target academic institutions in India, deploying the ReverseRAT remote access trojan to collect sensitive data.
Key Points:
- SideCopy, an APT group active since 2019, is shifting its focus from Indian government and defense entities to academic institutions.
- The attack chain uses a weaponized ZIP file containing a spoofed LNK file that executes an obfuscated HTA script via mshta.exe.
- The malware loads the ReverseRAT trojan into memory to evade disk-based detection and gather system metadata, screenshots, and passwords.
- Data is exfiltrated over port 5863 to a specific command-and-control server using a hard-coded encryption key.
Trellix researchers have documented a new campaign by the Pakistani APT group SideCopy, also known as TAG-140. While the group has historically targeted Indian defense forces and government officials, recent activity shows a strategic pivot toward academic institutions. The campaign begins with spear-phishing emails that deliver a ZIP archive containing a Windows shortcut file disguised as a Word document. This file triggers the execution of an obfuscated HTML Application using the mshta.exe utility, a common technique used to bypass standard security protocols.
Once executed, the malware performs a multi-stage deobfuscation process to load the ReverseRAT trojan directly into memory, avoiding detection by disk-based security tools. ReverseRAT has been used by SideCopy since early 2021 and is capable of collecting system information, installed software lists, screenshots, passwords, and clipboard content. The malware also establishes persistence through Windows Registry keys and exfiltrates the harvested data to a command-and-control server at dns.educationportals.biz via port 5863.
How can academic institutions better protect against spear-phishing attacks that use file type spoofing?
Learn More: The Hacker News
Want to stay updated on the latest cyber threats?
Source: r/pwnhub · by /u/_cybersecurity_