Overview
The threat actor known as SideCopy has expanded its targeting to academic institutions in India, demonstrating how universities and research environments are increasingly becoming part of the cyber-espionage landscape. Trellix researchers observed a campaign using spear-phishing to deliver ReverseRAT, a remote access trojan capable of stealing credentials, screenshots, files and clipboard data while providing attackers with remote command execution and persistent access. The important lesson for technology leaders extends beyond this particular campaign: valuable intelligence does not exist only inside government or defence networks. It also exists inside research institutions, universities and the organisations collaborating with them.
Spear-Phishing Starts the Attack
The campaign begins with a weaponised ZIP archive delivered through spear-phishing. Inside is a Windows shortcut disguised as a legitimate document, which retrieves an obfuscated HTML Application from attacker-controlled infrastructure. The malicious content is then executed using mshta.exe, a legitimate Microsoft utility designed to run HTML Applications. From there, several stages of obfuscation and reflective loading ultimately place the final RAT into memory. Trellix describes the chain as combining deceptive files, remote HTA staging, Registry persistence and fileless execution techniques intended to reduce the amount of malicious code written directly to disk.
Trusted Windows Tools Become Part of the Attack
One of the recurring techniques in the campaign is the abuse of mshta.exe, a legitimate Windows binary. Attackers frequently favour these trusted operating-system utilities because their presence alone may not immediately appear malicious. Instead of dropping a traditional executable and launching it directly, the attack uses legitimate Windows functionality to execute scripts and transition malicious payloads into memory. This reinforces an important defensive principle: the presence of a trusted binary does not automatically mean the activity around it is trusted. Security monitoring needs to examine context—what launched the process, what it downloaded and what happened next.
ReverseRAT Turns the Endpoint Into an Intelligence Platform
Once deployed, ReverseRAT provides extensive remote capabilities. Trellix reports that it can collect system information, installed software, screenshots, passwords and clipboard contents; manipulate files; execute commands; establish Registry-based persistence; upload data and open an interactive shell. For a research institution, this type of access could expose far more than individual user credentials. Academic environments may contain unpublished research, intellectual property, collaborative documents, grant information and access to partner organisations.
Why Academia Is an Attractive Target
Universities often combine characteristics that make security particularly challenging: large user populations, decentralised IT, visiting researchers, personal devices, external collaboration and extensive information sharing. At the same time, they may hold commercially or strategically valuable research. That combination can make academia attractive to espionage-focused attackers seeking information rather than immediate financial returns. SideCopy’s shift toward academic targets therefore illustrates a wider leadership issue: cyber risk should be assessed according to the value of information an organisation holds—not simply the industry label attached to it.
What IT Leaders Should Consider
Security teams should strengthen email and attachment filtering, monitor suspicious shortcut and HTA execution, and investigate unusual use of mshta.exe, especially when it is followed by scripting engines, network connections or Registry modifications. Endpoint detection should also look for behavioural chains rather than relying solely on malware signatures. Privileged credentials and sensitive research environments should be segmented, while administrative access should follow least-privilege principles. Most importantly, phishing awareness needs to reflect the increasingly targeted nature of these campaigns: a document that appears highly relevant to a researcher’s role may be precisely what makes the lure effective.
Expert in the Cloud Insight
SideCopy’s move into academia reinforces a broader cybersecurity reality: attackers target information value, not organisational stereotypes. Research institutions may not view themselves as traditional national-security targets, yet their intellectual property, partnerships and specialist knowledge can make them highly attractive to intelligence-focused adversaries.
For CIOs and IT managers, the question should therefore not simply be: “Are we a likely target?” It should be: “What information do we hold that somebody else would find valuable?”
Cyber resilience starts with understanding that value. If the data matters, the organisation protecting it matters too.
Leave a Reply