hacker-news · Crawled Sep 22, 2026

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

8 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

The Pakistan-based threat actor SideCopy has expanded its targeting to include academic institutions in India, using spear-phishing campaigns to deliver a remote access trojan called ReverseRAT. The attack chain begins with a malicious LNK file disguised as a PDF document, which executes an obfuscated HTA file via mshta.exe to load a reflective DLL payload. The malware establishes persistence through Windows Registry Run Keys, performs multi-stage in-memory deobfuscation, and exfiltrates data to a C2 server using encrypted traffic over port 5863.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 8 extracted

Type Value Detail
Domain docsportal[.]in Details →
Domain dns[.]educationportals[.]biz Details →
IP 45[.]61[.]157[.]22 Details →
Filename commskll.docx.lnk Details →
Filename startT.hta Details →
Filename appT.bat Details →
Filename ioluegnt.dll Details →
Filename commskl.docx Details →

MITRE ATT&CK TTPs 6 techniques