Pakistan-linked APT group SideCopy (also tracked as TAG-140) has expanded beyond its established focus on Indian government and defense organizations to target Indian academic institutions. Spear-phishing emails deliver ZIP archives containing a Windows LNK shortcut masquerading as a DOCX/PDF document; opening it retrieves an HTA payload from docsportal[.]in and launches it using the legitimate mshta.exe utility.
The multi-stage chain employs reflective DLL loading, .NET deserialization, in-memory payload execution, obfuscation, registry-based persistence, and self-deletion to limit file-based detection. The final ReverseRAT implant can collect system, user, credential, clipboard, and screenshot data; execute commands; manipulate files; open a shell; and exfiltrate data through encrypted C2 traffic over port 5863 to dns.educationportals[.]biz, which resolves to 45.61.157[.]22.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Seqrite Labs reported that SideCopy conducted a spear-phishing campaign against Afghanistan's Ministry of Finance using the open-source Xeno RAT.
SideCopy began using the ReverseRAT remote-access trojan, which supports reconnaissance, credential and clipboard theft, screenshots, command execution, file operations, persistence, and shell access.
SideCopy broadened its historical focus on Indian government and defense targets to academic institutions in India. The campaign delivered ZIP archives containing disguised LNK files that used mshta.exe to retrieve an HTA-based infection chain ending in ReverseRAT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.