"SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C said in a technical report.
SideCopy (TAG-140): expanding focus from government to Indian academia
Active since at least 2019, the actor tracked as SideCopy — also known as TAG-140 and reported to originate from Pakistan — has historically concentrated on Indian defense forces and government officials. Trellix's recent findings show a tactical shift: academic institutions in India are now explicit targets of spear-phishing operations that mirror the group's prior intelligence-collection campaigns. Seqrite Labs' June 2026 reporting, cited by Trellix, further traces the group's tooling to other regional campaigns, including a spear-phishing operation targeting Afghanistan's Ministry of Finance that used the open-source Xeno RAT.
Delivery chain: commskll.docx.lnk, mshta.exe, and docsportal[.]in
The documented infection chain begins with a weaponized ZIP archive containing a Windows shortcut file named "commskll.docx.lnk" that uses a spoofed PDF icon and a .DOCX extension to appear legitimate. When opened, that LNK fetches an obfuscated HTML Application (HTA) from a remote server at "docsportal[.]in" and executes it through the signed Windows binary mshta.exe. The HTA is self-deleting once the next stage takes hold, an anti-forensic routine Trellix highlights as part of the actor's layered obfuscation.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildPayload and persistence: ReverseRAT, ioluegnt.dll, and Registry Run Key
- The LNK-initiated HTA reflectively loads a DLL payload which acts as a dropper for three embedded components: appT.bat, startT.hta, and a decoy document named commskl.docx.
- appT.bat is used to create persistence via a Windows Registry Run Key that launches startT.hta with mshta.exe without requiring further user action.
- startT.hta contains heavily obfuscated code that deobfuscates a two-part XAML payload in memory and reflectively loads an embedded DLL called "ioluegnt.dll." To evade disk-based detection, the stage decodes a Base64-encoded string into volatile memory and activates it through .NET Deserialization.
- The DLL is a remote access trojan identified by Trellix as ReverseRAT, a tool SideCopy has employed since early 2021 to enable data exfiltration, remote execution, and persistence.
Command-and-control: hard-coded key, port 5863, and dns.educationportals[.]biz
ReverseRAT communicates with command-and-control infrastructure using an embedded cryptographic key: "NMXIKS09?:709,!~lnsYUS". Harvested data is exfiltrated over port 5863 to the domain "dns.educationportals[.]biz," which resolves to the IP address 45.61.157[.]22. Trellix's analysis lists the trojan's collection capabilities as including system metadata, installed-software inventories, screenshots, passwords and clipboard content, file operations, command execution, registry-based persistence setup, file uploads, and interactive shell sessions.
What this means for technologists, academic institutions, and policymakers
- Technologists and security teams: Trellix's detailed chain points to repeatable indicators — mshta.exe abuses, LNK files masquerading as .DOCX, the presence of appT.bat/startT.hta/ioluegnt.dll in memory or artifacts, and Registry Run Key persistence — that security analysts can prioritize when hunting for compromise. The hard-coded C2 key, port 5863, and the domain "dns.educationportals[.]biz" (resolving to 45.61.157[.]22) are precise defensive telemetry to examine for evidence of communication.
- Academic institutions and administrators in India: institutions historically considered lower-priority targets for nation-state actors are now explicitly within SideCopy's scope. The use of decoy documents (commskl.docx) and familiar collaboration-themed lures underscores the need to treat emailed archives and shortcuts with scrutiny.
- Policymakers and regional security planners: SideCopy's pivot from government entities to academia broadens the strategic intelligence-collection surface in the region. Seqrite Labs' linkage to a separate Xeno RAT campaign against Afghanistan's Ministry of Finance and Trellix's attribution to SideCopy/TAG-140 suggest a persistent, adaptable campaign pattern across multiple regional targets.
Trellix concludes that "the current activities of SideCopy underscore a disciplined and highly strategic approach to intelligence collection." By refining multilayered obfuscation and repeatedly abusing mshta.exe as an execution vector, SideCopy has extended an operational playbook that now reaches academic networks as well as the government and defense targets it has long pursued. That expansion — coupled with in-memory-only payload reconstruction and an embedded cryptographic key for C2 — leaves clear forensic fingerprints, even as the actor seeks to erase its on-disk traces.




