SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

Summary

The threat actor SideCopy is now targeting academic institutions in India with spear-phishing attacks, expanding from their previous focus on government entities. These campaigns utilize mshta.exe to execute malicious scripts and bypass security measures.

IFF Assessment

FOE

This article details a new tactic by a threat actor to compromise academic institutions, indicating an increased risk and potential for exploitation.

Defender Context

Defenders should be aware of this shift in SideCopy's targeting and the use of mshta.exe as a potential execution vector. Academic institutions are now a higher-value target, requiring enhanced vigilance against spear-phishing attempts and robust endpoint detection to identify and block malicious script execution.

Read Full Story →