SideCopy threat actor has expanded targeting beyond Indian government entities to include academic institutions in India, according to research published by Trellix on September 22, 2026.
The campaign uses spear-phishing to deliver ReverseRAT malware, with an attack chain that abuses mshta.exe to execute malicious scripts and bypass security controls. The targeting expansion represents a strategic shift as SideCopy seeks intellectual property and research data from Indian universities and research centers.
SideCopy Historically Focused on Indian Government Targets
SideCopy has primarily targeted Indian government entities in prior campaigns, focusing on ministries, defense organizations, and diplomatic offices. The group’s operations have centered on espionage objectives—stealing classified documents, intercepting communications, and gathering intelligence on government policy and security operations.
The threat actor’s name derives from its tactic of mimicking the tools and techniques of another group, SideWinder, which also targets South Asian entities. SideCopy’s toolset and infrastructure often resemble SideWinder operations, complicating attribution and defensive responses.
Academic Institutions Now Targeted Alongside Government Entities
Trellix researchers documented SideCopy’s expansion to Indian academic institutions on September 22, 2026. The targeting shift brings universities, research centers, and educational organizations into the threat actor’s operational scope.
Academic institutions hold research data, intellectual property, student and faculty personal information, and collaborative research partnerships with government and industry. For espionage-focused threat actors, universities represent a secondary intelligence source—one that is often less defended than government networks but still holds valuable data.
Indian academic institutions conducting defense research, technology development, or policy analysis are particularly attractive targets. SideCopy’s government focus suggests the group seeks intelligence with strategic or military value, making universities involved in sensitive research a logical expansion.
Spear-Phishing Delivers ReverseRAT via mshta.exe Abuse
The campaign uses spear-phishing emails to deliver ReverseRAT, a remote access trojan that grants the attacker control over compromised systems. The malware allows command execution, file exfiltration, screen capture, and keystroke logging.
The attack chain abuses mshta.exe, a legitimate Windows utility designed to execute Microsoft HTML Application files. Attackers use mshta.exe to run malicious scripts while evading detection, as security tools often allowlist the legitimate Windows binary.
When a victim opens the phishing email attachment or clicks a malicious link, the payload invokes mshta.exe to execute a script that downloads and installs ReverseRAT. The use of a trusted Windows binary reduces the likelihood of antivirus or endpoint detection and response tools flagging the execution as malicious.
Trellix Published Research Disclosure September 22
Trellix documented the SideCopy academic targeting campaign on September 22, 2026. The research identified the tactical use of mshta.exe abuse and the deployment of ReverseRAT as the primary malware payload.
The disclosure did not name specific targeted institutions, provide a count of compromised universities, or describe the data exfiltrated during the campaign. The absence of victim details may reflect Trellix’s coordination with affected organizations or a decision to limit public disclosure of sensitive targeting information.
Indian Academic Institutions Face Increased Espionage Risk
The SideCopy targeting expansion places Indian academic institutions in the crosshairs of an active espionage threat actor. Universities must now defend against the same tradecraft SideCopy has deployed against government targets, including spear-phishing, mshta.exe-based malware delivery, and ReverseRAT deployment.
Academic networks often have weaker security postures than government or defense organizations. Universities prioritize open collaboration, guest access for visiting researchers, and broad internet connectivity—all of which create larger attack surfaces than isolated government networks.
The research community’s reliance on email for document sharing and collaboration also makes spear-phishing a particularly effective tactic. Faculty and researchers regularly receive unsolicited emails with attachments from unknown senders, making malicious phishing emails harder to distinguish from legitimate academic correspondence.
Implications for Indian Higher Education and Research Security
SideCopy’s shift to academic targeting signals a broader trend of APT groups seeking intellectual property and research data from universities. Indian institutions conducting research in defense technology, cybersecurity, artificial intelligence, or strategic policy are high-value targets for espionage operations.
Universities should implement email security controls to detect and block spear-phishing, restrict execution of mshta.exe or monitor it for abuse, and educate faculty and researchers on phishing recognition. Endpoint detection and response tools should flag mshta.exe invocations that attempt to download remote scripts or execute suspicious payloads.
Research data should be classified by sensitivity, with high-value intellectual property isolated from general university networks and protected by additional access controls. Institutions conducting defense-related or government-funded research must apply security controls commensurate with the sensitivity of the work, not the typical academic network’s open-access model.
Trellix’s disclosure provides Indian academic institutions with actionable intelligence on the threat actor’s tactics. Universities can now search for mshta.exe abuse in endpoint logs, review email gateways for ReverseRAT delivery attempts, and harden defenses against the specific attack chain SideCopy has deployed against this sector.
The expansion also raises questions about whether SideCopy will continue broadening its targeting scope beyond government and academia to include Indian private sector research organizations, think tanks, or technology companies. Threat actors that successfully penetrate a new sector often expand operations within that sector once initial reconnaissance and tooling prove effective.
