SideCopy, an APT group focused on Indian targets, has expanded operations to include academic institutions through spear-phishing campaigns delivering ReverseRAT malware. The threat actor, previously documented targeting Indian government entities, now pursues universities and research organizations with renewed tactical sophistication.

Trellix researchers identified the shift in targeting scope while analyzing recent SideCopy campaigns. The group deploys spear-phishing emails crafted to appear legitimate to academic staff and researchers. These messages contain malicious attachments or links that, when activated, trigger a multi-stage infection chain beginning with the abuse of mshta.exe, a Windows utility designed for HTML Application execution.

The mshta.exe abuse technique allows attackers to bypass traditional application whitelisting and endpoint detection mechanisms. Once executed, mshta.exe retrieves and runs malicious scripts from remote servers, establishing initial compromise on target systems. This approach delivers ReverseRAT, a remote access trojan that grants attackers interactive command execution, file exfiltration, and persistence capabilities on compromised machines.

SideCopy has operated since at least 2019, maintaining consistent focus on Indian government organizations. The group demonstrates moderate operational security practices, regularly rotating infrastructure and adjusting malware signatures. Intelligence analysts assess SideCopy as likely state-sponsored, operating under strategic direction aligned with Indian espionage priorities. The expansion to academic targets suggests broader reconnaissance objectives targeting scientific research, intellectual property, and policy development within Indian institutions.

Academic institutions present attractive targets for several operational reasons. Universities host sensitive research in defense, aerospace, nuclear technology, and telecommunications sectors. Faculty networks often include government advisors and policy architects. Research collaboration databases contain institutional contact information and project details. Academic email systems frequently employ weaker security controls than government infrastructure, enabling higher compromise success rates.

The technical execution reflects operational continuity. SideCopy employs commodity remote access tools wrapped in custom delivery frameworks. The group shows no inclination toward zero-day exploitation or advanced evasion techniques, instead relying on social engineering effectiveness and victim carelessness. Target selection appears deliberate rather than opportunistic, indicating prior reconnaissance of academic organizational structures.

Organizations in Indian academia should implement specific defensive measures. Email gateway filtering requires configuration to detect executable attachments and suspicious script execution patterns. Endpoint detection and response systems need tuning to flag mshta.exe launching child processes or establishing outbound connections. User security awareness training should emphasize verification of sender identities through direct contact and validation of unexpected requests before credential entry.

Windows Defender Application Guard can restrict mshta.exe functionality. Network segmentation isolates research systems from general academic networks. Disabling mshta.exe entirely represents the strongest mitigation where HTML Application functionality remains unused. Organizations should conduct email security audits to identify credential harvesting infrastructure and educational phishing simulations to assess staff susceptibility.

SideCopy's operational expansion reflects standard APT evolution. Groups diversify targeting to access broader intelligence pools and identify new operational access points. The academic sector provides legitimate cover for espionage activities while maintaining deniability. Defense organizations across South Asia should expect similar targeting emphasis on research institutions and technology development centers.