A sophisticated spear-phishing campaign, attributed to a group known as SideCopy, has been discovered targeting Indian academia with a custom-made malware tool called ReverseRAT. This operation marks an expansion of the group’s activities, previously focused on India’s government and private sector institutions.
SideCopy’s ReverseRAT malware allows the attackers to gain remote access to compromised systems, granting them the ability to monitor user activity, capture sensitive data, and potentially install additional malicious software. The spear-phishing emails used in this campaign are tailored to deceive recipients into installing the malware, often masquerading as legitimate messages from academics or institutions. To evade detection, the attackers employ a complex system of encrypted communication channels and proxy servers.
The scope of SideCopy’s operation is significant, with multiple Indian academic institutions falling prey to their tactics. These compromised entities include research centers, universities, and even government-funded scientific organizations. It’s worth noting that these targets are likely chosen due to their possession of sensitive data or valuable intellectual property. The attackers’ primary goal appears to be accessing and exfiltrating this information for potential exploitation.
This campaign highlights the persistent threat posed by targeted attacks, particularly in regions like India where cybercrime is on the rise. SideCopy’s ability to adapt their tactics to evade detection and successfully compromise high-profile targets underscores the need for heightened vigilance within vulnerable sectors. Furthermore, the presence of ReverseRAT on compromised systems creates a backdoor that can be exploited at any time by the attackers.
The use of spear-phishing as an attack vector allows SideCopy to bypass traditional security measures, taking advantage of human psychology and exploiting the trust between individuals in academic circles. This approach underscores the importance of not only robust cybersecurity infrastructure but also employee education on recognizing and reporting suspicious activity.
As a result of this campaign, we urge academia and research institutions to exercise extreme caution when receiving unsolicited emails or attachments, especially those purporting to be from known colleagues or entities within their own organizations. Implementing regular security audits, providing user awareness training, and maintaining up-to-date defenses against the latest threats will help mitigate the risk of falling victim to such targeted attacks.
Source: The Hacker News — 2026-09-22