SideCopy Phishes Indian Universities With Fake Docs

The Hacker News · High sophistication
Last updated September 22, 2026

Pakistan-linked APT group SideCopy expanded from targeting Indian government entities to targeting Indian academic institutions using spear-phishing. The emails deliver a weaponized ZIP containing a fake “document” shortcut that launches mshta.exe to pull down and run malware, ultimately installing the ReverseRAT remote access trojan for data theft and remote control.

Key findings

  • SideCopy is using spear-phishing to target academic institutions in India, expanding beyond prior focus on government/defense.
  • The lure is a weaponized ZIP archive containing a Windows shortcut (LNK) disguised as a document (spoofed PDF icon + .DOCX extension).
  • The attack abuses mshta.exe to execute a downloaded HTA script and load payloads primarily in memory to evade detection.
  • ReverseRAT is used for data theft and remote access (screenshots, passwords, clipboard, command execution, persistence).
  • Observed infrastructure included docsportal[.]in and dns.educationportals[.]biz (port 5863), resolving to 45.61.157[.]22.

Who’s being targeted

  • Commonly targeted roles: Faculty, Researchers, University administration, IT helpdesk / desktop support, Security awareness training audiences in higher education.
  • Affected industries: Higher education, Academic research, Government (historical targeting), Defense (historical targeting).
  • Attack channels: email, website.
  • Impersonated: Academic/administrative contact (unspecified in article), Document portal / internal docs site (implied by attacker domain naming).

Awareness takeaways

  • Treat ZIP-delivered ‘documents’ as high risk, especially when the filename contains double extensions like .docx.lnk.
  • If a document requires running scripts or Windows utilities (like mshta.exe), stop and report it, documents shouldn’t need that to view content.
  • Be cautious of ‘portal’/‘education’ domains that look legitimate but are not official; verify links through known university channels.

Red flags to watch for

  • A “document” file name that includes multiple extensions (e.g., .docx.lnk)
  • ZIP attachment used for a simple document share
  • File icon/extension mismatch (spoofed PDF icon but not a real PDF)
  • Unexpected ‘portal’ domain not matching the university’s real domain
  • Opening the attachment triggers a background download
  • Use of Windows scripting components (mshta.exe) for a document workflow
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Please review the attached document (ZIP). Open commskll.docx to view.” Looks routine, right? But inside that ZIP, SideCopy hides a fake document: commskll.docx.lnk, with a spoofed PDF icon. Double-click it, and it quietly launches mshta.exe, pulling malware from docsportal.in to install ReverseRAT. Here’s the giveaway: real documents don’t need ZIPs, double extensions like .docx.lnk, or to fire up tools like mshta.exe or weird portals like docsportal.in or dns.educationportals.biz in the background. If you see a ZIP-delivered ‘document’ with a double extension like .docx.lnk, stop. Don’t open it, forward it to IT security and delete the email.

Similar attacks

Korea APTs Push LNK “Resume” Spear‑Phish

Korea APTs Push LNK “Resume” Spear‑Phish

AhnLab reports that many APT attacks targeting organizations in South Korea in July 2026 started with spear‑phishing emails that delivered malicious Windows shortcut (LNK) files disguised as legitimate documents (including resumes). When opened, the LNK runs scripts that install…

August 28, 2026
Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
Resume Phish Hit Brazil Banks; AI Aided Ops

Resume Phish Hit Brazil Banks; AI Aided Ops

Two real, ongoing intrusion campaigns targeted organizations in Latin America, including a Mexican transportation organization and Brazil’s financial sector. In the Brazil campaign, attackers reportedly got in via a resume-themed phishing attachment, then attempted to download and run tunneling…

September 3, 2026
Phishers Hide Lua Malware as “.TTF Font”

Phishers Hide Lua Malware as “.TTF Font”

A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but actually hide a Lua-based loader. Once executed, the loader uses stealthy, mostly in-memory techniques to install remote access trojans and…

July 16, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026
Tax and SSA Phish Push Cruciferra Malware Loader

Tax and SSA Phish Push Cruciferra Malware Loader

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included…

July 27, 2026