SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
Summary
The threat actor SideCopy is now targeting academic institutions in India with spear-phishing attacks, expanding from their previous focus on government entities. These campaigns utilize mshta.exe to execute malicious scripts and bypass security measures.
IFF Assessment
FOE
This article details a new tactic by a threat actor to compromise academic institutions, indicating an increased risk and potential for exploitation.
Defender Context
Defenders should be aware of this shift in SideCopy's targeting and the use of mshta.exe as a potential execution vector. Academic institutions are now a higher-value target, requiring enhanced vigilance against spear-phishing attempts and robust endpoint detection to identify and block malicious script execution.