Pakistan-Linked SideCopy Hackers Expand Spear-Phishing Attacks to Indian Universities
A threat actor known as SideCopy, believed to originate from Pakistan and linked to the Transparent Tribe cluster, has been observed targeting academic institutions in India with spear-phishing campaigns. This marks a shift from the group's historical focus on Indian defence forces and government officials, according to researchers at Trellix.
The attack begins with a booby-trapped ZIP file containing a disguised shortcut file made to look like a PDF or Word document. When opened, it quietly downloads a malicious script that abuses a legitimate Windows tool (mshta.exe) to bypass security checks, ultimately loading a remote access trojan directly into the computer's memory. The malware also deletes traces of itself from disk once running, and uses memory-based techniques to avoid detection by traditional antivirus tools.
SideCopy has been active since at least 2019 and has previously targeted government bodies in the region, including a recent campaign against Afghanistan's Ministry of Finance. Its expansion into academic targets suggests the group is broadening its reach to gather intelligence from a wider range of institutions.