Threat Intelligence

Pakistan-Linked SideCopy Hackers Expand Spear-Phishing Attacks to Indian Universities

The Hacker News · 22 Sept 2026
Key Takeaway Australian businesses and institutions that deal with academic or research partners should train staff to be wary of unexpected ZIP attachments and disguised shortcut files, as these are increasingly used to deliver hidden malware.

A threat actor known as SideCopy, believed to originate from Pakistan and linked to the Transparent Tribe cluster, has been observed targeting academic institutions in India with spear-phishing campaigns. This marks a shift from the group's historical focus on Indian defence forces and government officials, according to researchers at Trellix.

The attack begins with a booby-trapped ZIP file containing a disguised shortcut file made to look like a PDF or Word document. When opened, it quietly downloads a malicious script that abuses a legitimate Windows tool (mshta.exe) to bypass security checks, ultimately loading a remote access trojan directly into the computer's memory. The malware also deletes traces of itself from disk once running, and uses memory-based techniques to avoid detection by traditional antivirus tools.

SideCopy has been active since at least 2019 and has previously targeted government bodies in the region, including a recent campaign against Afghanistan's Ministry of Finance. Its expansion into academic targets suggests the group is broadening its reach to gather intelligence from a wider range of institutions.

spear-phishing APT malware remote access trojan India

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.