HackerFeeds

CyberSecurity News

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The Hacker News
· September 22, 2026

AI summary

The threat actor SideCopy is now targeting academic institutions in India using spear-phishing tactics, marking an expansion of their focus beyond government entities. SideCopy's campaigns typically start with spear-phishing efforts that exploit mshta.exe to run malicious scripts and evade standard security measures. This approach allows them to circumvent usual security protocols. Researchers at Trellix have observed this activity, highlighting the group's evolving targeting strategy. SideCopy's shift to targeting academia in India indicates a broadening of their objectives. The use of spear-phishing and exploitation of mshta.exe is a key part of their operational methodology.

Countries in focus

Read the full article at The Hacker Newsthehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.