Wire Observer.
Technology

SideCopy Extends Cyber Espionage to Indian Universities with ReverseRAT Phishing Campaign

SideCopy Extends Cyber Espionage to Indian Universities with ReverseRAT Phishing Campaign

Cyber‑espionage group SideCopy has broadened its attack portfolio to include Indian academic institutions, employing reverse‑engineered remote access tools (ReverseRAT) delivered through targeted spear‑phishing emails. The shift marks a notable departure from the group’s earlier concentration on government agencies, signaling a strategic diversification of its intelligence‑gathering efforts.

Security researchers observed that the new campaign uses highly crafted lures that mimic legitimate academic communications, such as conference invitations, research grant notices, and collaborative project requests. Recipients are prompted to open malicious attachments or click links that install the ReverseRAT payload, granting the attackers persistent access to the victim’s network and data.

While the group’s previous operations focused on extracting policy‑related information from ministries and state bodies, the move toward universities suggests a pursuit of research data, intellectual property, and potentially sensitive scientific findings. Indian higher‑education institutions, which often collaborate with international partners and handle cutting‑edge research, present a valuable trove of information for state‑aligned threat actors.

Cyber‑defense firms note that the tactics employed by SideCopy are consistent with broader trends in the region, where threat actors increasingly target the academic sector to harvest credentials, exfiltrate research papers, and establish footholds for future operations. The use of ReverseRAT—a tool that can bypass many conventional endpoint protections—underscores the group’s technical sophistication and its willingness to adapt existing malware to evade detection.

University IT departments have been urged to reinforce email security protocols, conduct regular phishing awareness training, and deploy advanced threat‑monitoring solutions capable of identifying anomalous behavior associated with remote access tools. Some institutions have already begun reviewing their incident‑response plans in light of the emerging threat.

Analysts caution that the expansion of SideCopy’s target set could foreshadow additional campaigns aimed at other sectors that handle valuable data, such as healthcare and finance. Ongoing monitoring and information sharing among Indian cybersecurity agencies, academia, and private security firms will be critical to mitigate the group’s evolving tactics and to protect the nation’s research ecosystem.

Source: feedburner
Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related