Find notable cyber news and cases, enriched with sources, timelines, and signals.

SideCopy spear-phishing campaign targeting academic institutions in India

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The SideCopy campaign has expanded into academic institutions in India, extending a long-running spear-phishing operation beyond its traditional government targets and raising the risk of credential theft and remote compromise. The latest delivery chain uses a weaponized ZIP archive, a spoofed LNK file, and mshta.exe to fetch malicious content and stage payloads. The campaign deploys ReverseRAT, which supports data exfiltration, remote execution, and persistence.

Related Happenings

Cruciferra crypter service's underground operating model

Threat Actor Meta
H score29 First: 27.07.2026 13:51 Last: 27.07.2026 13:51 Sources 1

About this happening: Researchers observed Cruciferra operating as a paid crypter service used by multiple unrelated threat clusters, expanding the underground malware-delivery ecosystem an...

Operation DragonReturn tax-phishing campaign targeting Indian taxpayers

Campaign
H score31 First: 06.07.2026 13:58 Last: 06.07.2026 13:58 Sources 1

About this happening: The Operation DragonReturn campaign is using spear-phishing and fake tax-filing lures to push remote access trojans into Indian taxpayer and finance environments, crea...

Latest development: 08.07.2026 03:00

Updated reporting on July 8, 2026 added Cyderes findings that Operation DragonReturn also uses fake websites impersonating the Indian Income Tax Department to deliver ZIP archives disguised as the common offline utility. The same chain deploys two implants, including a Gh0st RAT derivative that connects to kkxqbh[.]top on port 6666 and an AsyncRAT-family RAT that connects to ouewop[.]com on port 6351, while separate C2 channels, session-wide injection, and multiple initial access vectors improve persistence and resilience.

SideCopy Operation XENOFISCAL spear-phishing campaign targeting Afghan finance entities

Campaign
H score25 First: 02.06.2026 12:05 Last: 02.06.2026 12:05 Sources 1

About this happening: The SideCopy-linked Operation XENOFISCAL spear-phishing campaign is targeting Afghanistan's Ministry of Finance and related provincial finance offices with Xeno RAT*...

APT36 / SideCopy phishing-led campaign targeting Indian defense organizations

Campaign
H score38 First: 11.02.2026 16:52 Last: 11.02.2026 16:52 Sources 1

How related: "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C said in a technical report.

About this happening: A phishing-led APT36 / SideCopy campaign is targeting Indian defense and government-linked organizations and has now expanded to academic institutions in India. Th...

Latest development: 22.09.2026 10:52

SideCopy targeted academic institutions in India with spear-phishing lures that delivered a weaponized ZIP archive containing commskk.docx.lnk, abused mshta.exe to fetch docsportal[.]in, and loaded a DLL payload that staged ReverseRAT, expanding the campaign beyond prior government-targeted activity.

Timeline

  1. 22.09.2026 10:52 2 articles · 3h ago

    SideCopy targets academic institutions in India with ReverseRAT spear-phishing

    Initial Disclosure

    SideCopy expanded its India-focused spear-phishing operations from government targets to academic institutions in India, using a weaponized ZIP archive that contains a spoofed Windows shortcut named commskll.docx.lnk. The lure abuses mshta.exe to fetch obfuscated HTA content from docsportal[.]in, reflectively load a DLL, and stage ReverseRAT for data exfiltration, remote execution, persistence, and file theft; the command-and-control traffic uses the hard-coded key NMXIKS09?:709,!~lnsYUS and exfiltrates data to dns.educationportals[.]biz over port 5863.

    Show sources