A threat actor known as SideCopy has been spotted using spear-phishing tactics to target academic institutions in India, expanding their attack scope beyond government entities. According to a technical report from Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C, SideCopy's campaign operations begin with spear-phishing attacks that leverage the mshta.exe executable to execute malicious scripts and bypass security protocols. The latest attack chain documented by Trellix uses spear-phishing to deliver a weaponized ZIP archive, which contains a Windows shortcut (LNK) with a spoofed PDF icon and a .DOCX extension ("commskll.docx.lnk") to make the malicious file appear legitimate.

The malware employs a self-deletion routine to remove the HTA file once the secondary stage is initiated.

It collects system metadata, installed software list, screenshots, passwords, and clipboard content; performs file operations; runs commands; sets up persistence via the Registry; uploads files; and establishes a shell session. The command-and-control traffic is encrypted with a hardcoded cryptographic key, "NMXIKS09?:709,!~lnsYUS." The harvested data is exfiltrated through a port 5863 to "dns.educationportals[.

]biz," which resolves to the IP address "45.61.157[.]22." The ongoing activities of SideCopy demonstrate a well-structured and strategic approach to intelligence gathering.