MediumII Cyber Warfare & Critical Infrastructure22 September 2026, Tuesday
SideCopy targets Indian universities with ReverseRAT: data exfiltrated through port 5863
According to a Trellix analysis published on 22 September 2026, the Pakistan-based SideCopy group has widened its targeting from government and defence institutions to academic institutions in India; the phishing chain loads ReverseRAT through mshta.exe.
As reported by The Hacker News on 22 September 2026 on the basis of Trellix research, the attack chain begins with a weaponised ZIP archive. Inside the archive is a Windows shortcut (LNK) carrying a PDF icon and imitating a .DOCX extension; the shortcut downloads an encrypted HTML Application (HTA) from a remote server and runs it through mshta.exe, which in turn reflects a DLL payload into memory and launches ReverseRAT. The group has been active since at least 2019, a record of 7 years of activity. ReverseRAT itself has been in use since early 2021, roughly 5 years. SideCopy is also tracked under the name TAG-140 and overlaps with the Transparent Tribe cluster.
The technical indicators are concrete: collected data is sent through port 5863 to the address dns.educationportals[.]biz, which resolves to the IP address 45.61.157[.]22; the campaign uses the spoofed domain docsportal[.]in as a lure and encrypts command-and-control traffic with an embedded static key. ReverseRAT collects system information, lists of installed software, screenshots, passwords and clipboard contents; it performs file operations, runs commands, establishes persistence through the registry and opens a shell session.
The report gives no CVE number; the chain abuses Windows's legitimate mshta.exe tool rather than a software vulnerability, so there is no patch date in the classic sense. The number of institutions affected has not been disclosed and could not be independently verified. On the defensive side the only concrete measure is restricting script interpreters such as mshta.exe, PowerShell and cmd.exe through corporate policy.
Talay assessment
Bottom line
SideCopy shifting its target in 7 years of activity from defence and the bureaucracy to universities shows intelligence gathering reaching down into the research and skilled-personnel layer. The chain resting on the legitimate mshta.exe tool rather than a CVE means it cannot be closed by patching; defence depends on configuration policy. Because the number of institutions has not been disclosed the scale is unknown, and the most likely direction is that the campaign continues quietly.
Likely effects
- Indian academic networksNegativeWeeks
University networks have lower defensive maturity than government institutions; unless traffic to port 5863 is blocked, research data and credentials could leak for an extended period.
- South Asian cyber tensionNegative1–6 months
A Pakistan-based group widening its target surface shows border tension between the 2 countries spreading into the cyber domain and makes retaliatory campaigns more likely.
- Corporate defence in TürkiyeUncertain1–6 months
Chains based on mshta.exe that need no CVE are not closed by patching; restricting script interpreters by policy is the same requirement for university and public networks in Türkiye.
Possibilities, ranked
- 1The campaign continues quietly55%
It continues with new domains after the infrastructure is changed, and the number of institutions affected is not disclosed.
Watch: Publication of command-and-control indicators beyond dns.educationportals[.]biz and 45.61.157[.]22
- 2An official advisory is issued30%
India's national cyber agency publishes an indicator list and configuration guidance for academic institutions.
Watch: A CERT-In advisory bulletin or an official warning sent to universities
- 3The scale becomes public15%
The number of institutions affected and the volume of data stolen become public and the incident reaches the national agenda.
Watch: A data breach notification from a university or a quantified report from a second security firm
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Years the group has been active▲ 7 years