Executive Summary
The Pakistan-linked APT group SideCopy has expanded its targeting beyond Indian government entities to include academic institutions through sophisticated spear-phishing campaigns in 2026. The threat actors utilize weaponized ZIP archives containing malicious LNK files that abuse mshta.exe to execute obfuscated HTML applications, ultimately deploying the ReverseRAT malware for data exfiltration and remote access. The attack chain employs multi-stage obfuscation, anti-forensic self-deletion routines, and encrypted command-and-control communications to evade detection while harvesting system metadata, credentials, and sensitive documents from compromised networks.
This incident highlights the evolving threat landscape where state-sponsored groups are diversifying their target profiles to include educational institutions, recognizing their value as repositories of intellectual property and research data. The sophistication of SideCopy's techniques demonstrates the growing challenge organizations face in defending against adaptive APT groups that continuously refine their tradecraft.
Why This Matters Now
State-sponsored APT groups are increasingly targeting academic institutions as repositories of valuable intellectual property and research data, requiring organizations to reassess their security posture against sophisticated spear-phishing campaigns and implement comprehensive zero-trust controls.
Attack Path Analysis
SideCopy executed a sophisticated spear-phishing campaign targeting Indian academic institutions using weaponized ZIP archives containing malicious LNK files. The attack leveraged mshta.exe abuse for initial execution, deployed ReverseRAT for persistence and remote access, established encrypted C2 communications on port 5863, and exfiltrated sensitive academic data including credentials, documents, and system information to attacker-controlled infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Spear-phishing emails delivered weaponized ZIP archives containing LNK files disguised as legitimate documents (commskll.docx.lnk) that executed mshta.exe to fetch and run malicious HTA payloads from docsportal[.]in
MITRE ATT&CK® Techniques
Spearphishing Attachment
Mshta
Registry Run Keys / Startup Folder
Process Injection
Deobfuscate/Decode Files or Information
Screen Capture
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA Zero Trust Maturity Model 2.0 – Analysis and Response
Control ID: DE.AE-2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Direct targeting of academic institutions by SideCopy APT through spear-phishing campaigns deploying ReverseRAT, exposing research data and institutional credentials to exfiltration.
Government Administration
Historical primary target of SideCopy's espionage operations, facing advanced persistent threats through mshta.exe exploitation and encrypted command-and-control infrastructure for intelligence collection.
Defense/Space
Previously targeted Indian defense forces face ongoing APT campaigns with sophisticated multi-stage obfuscation, anti-forensic techniques, and persistent remote access trojan deployment capabilities.
Information Technology/IT
Critical infrastructure supporting targeted sectors requires enhanced egress filtering, zero trust segmentation, and threat detection capabilities to mitigate lateral movement and data exfiltration.
Sources
- SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishinghttps://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.htmlVerified
- SideCopy Threat Intel: MSHTA Execution and RAT Deploymenthttps://www.trellix.com/blogs/research/sidecopy-threat-intel-mshta-execution-rat-deployment/Verified
- SideCopy Threat Actor Profilehttps://cyble.com/threat-actor-profiles/sidecopy/Verified
- Pakistan-linked SideCopy Targets Afghanistan's Ministry of Financehttps://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained SideCopy's lateral movement and data exfiltration by implementing segmented network access and controlled egress policies. The attack's blast radius across academic network systems would likely have been significantly reduced through workload isolation and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise execution would likely have proceeded, but subsequent network reconnaissance and discovery activities may have been constrained through segmented visibility controls and restricted network access patterns.
Control: Zero Trust Segmentation
Mitigation: ReverseRAT deployment would likely have proceeded on the initial compromised system, but the malware's operational scope and access to sensitive resources may have been constrained through identity-aware access controls and workload isolation.
Control: East-West Traffic Security
Mitigation: Lateral movement across academic network systems would likely have been significantly constrained, with east-west traffic enforcement blocking or limiting unauthorized inter-workload communications and file access operations between compromised and target systems.
Control: Multicloud Visibility & Control
Mitigation: C2 communications may have been detected and monitored through enhanced visibility controls, though the encrypted channel could have maintained basic connectivity while reducing the attacker's operational confidence and command execution frequency.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration activities would likely have been constrained through controlled egress policies, potentially blocking or limiting the volume and types of sensitive academic data that could be transmitted to external attacker infrastructure.
Residual impact to academic research data and institutional credentials would likely be limited to initially compromised systems, with reduced exposure of sensitive intellectual property and constrained attacker access to broader institutional resources.
Impact at a Glance
Affected Business Functions
- Academic Research Systems
- Student Information Systems
- Faculty Communications
- Institutional Data Management
Estimated downtime: 7 days
Estimated loss: $150,000
Academic research data, faculty and student personal information, institutional communications, and potentially classified government-sponsored research projects. The RAT capabilities include system metadata collection, installed software enumeration, screenshots, passwords, clipboard content, and file operations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to block unauthorized outbound communications to suspicious domains like dns.educationportals[.]biz and detect data exfiltration attempts
- • Deploy zero trust segmentation with least privilege access controls to prevent lateral movement between academic network segments and limit blast radius of compromised endpoints
- • Enable multicloud visibility and control with traffic observability to detect anomalous C2 communications patterns and suspicious automation behaviors across the network
- • Implement threat detection and anomaly response capabilities to identify covert tools, unauthorized remote access, and baseline deviations from normal academic network activity
- • Deploy inline IPS with Suricata signatures to detect and block known exploit patterns, malicious payloads, and CVE-based attacks before they can establish persistence



