SideCopy, a threat actor that has historically targeted Indian government bodies, has now been observed turning its attention to academic institutions in the country. According to The Hacker News, the campaign relies on spear-phishing lures to deliver ReverseRAT, a remote access trojan.
The shift is significant because it widens the group's pool of potential victims to include universities and research centers. The report notes that SideCopy's operations typically begin with spear-phishing, but it does not provide further details on the specific lure themes or the full infection chain in this latest wave.
This expansion suggests the group may be seeking footholds in academic networks, possibly to reach individuals involved in sensitive research or policy work. The source contains only that one report, so there are no differing accounts to compare—just a single observation of an evolving threat pattern.