hacker-news · Crawled Sep 22, 2026
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
8 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
The Pakistan-based threat actor SideCopy has expanded its targeting to include academic institutions in India, using spear-phishing campaigns to deliver a remote access trojan called ReverseRAT. The attack chain begins with a malicious LNK file disguised as a PDF document, which executes an obfuscated HTA file via mshta.exe to load a reflective DLL payload. The malware establishes persistence through Windows Registry Run Keys, performs multi-stage in-memory deobfuscation, and exfiltrates data to a C2 server using encrypted traffic over port 5863.
AI-extracted · verify before operational use