Date: 09/18/2026
Severity: High
Summary
SideCopy has expanded its cyber operations beyond its traditional focus on government officials and high-ranking personnel to include academic institutions. The group typically uses spear-phishing campaigns to gain initial access and deliver malicious payloads. Attackers abuse mshta.exe to execute malicious scripts and bypass standard security controls. This technique enables the deployment of a Remote Access Trojan (RAT) within targeted environments. The RAT serves as a key component of SideCopy’s infrastructure for surveillance and data exfiltration activities.
Indicators of Compromise (IOC) List
Domain/URLs | dns.educationportals.biz https://docsportal.in/public/reps/com/161.php |
IP Address | 45.61.157.22 |
Hash | 0647336477bdd277450b0c36f104f3f82da721e98d56b67bbeeec05cc48f2d1c
0e0b77f79fe5d06f11de2959559379e94d62512e073c267b481a58d19d265240
34c20f5abc04375822f3f68e3e9915c7e388e8adb1ade597672920d53f2c067c
ac340859805220f97f98b299b32d82b1ccbb2c04c8c09516f3937feda937af80
8435ec938ca225c3131a624715832845ad9adc5faa93488486bc19c094b4d3ec
a5e36cf05bcc9ac4e9ebf2a13f95aef8e3847086fe7340c36d6aba6616ae1174
cceee5c983360842351ffdb8979676fd2fccd4e4c387ac77e4506291d8083c5c
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "dns.educationportals.biz" or url like "dns.educationportals.biz" or siteurl like "dns.educationportals.biz" or domainname like "https://docsportal.in/public/reps/com/161.php" or url like "https://docsportal.in/public/reps/com/161.php" or siteurl like "https://docsportal.in/public/reps/com/161.php" |
Detection Query 2 : | dstipaddress IN ("45.61.157.22") or srcipaddress IN ("45.61.157.22") |
Detection Query 3 : | sha256hash IN ("0e0b77f79fe5d06f11de2959559379e94d62512e073c267b481a58d19d265240","cceee5c983360842351ffdb8979676fd2fccd4e4c387ac77e4506291d8083c5c","34c20f5abc04375822f3f68e3e9915c7e388e8adb1ade597672920d53f2c067c","0647336477bdd277450b0c36f104f3f82da721e98d56b67bbeeec05cc48f2d1c","ac340859805220f97f98b299b32d82b1ccbb2c04c8c09516f3937feda937af80","8435ec938ca225c3131a624715832845ad9adc5faa93488486bc19c094b4d3ec","a5e36cf05bcc9ac4e9ebf2a13f95aef8e3847086fe7340c36d6aba6616ae1174")
|
Reference:
https://www.trellix.com/blogs/research/sidecopy-threat-intel-mshta-execution-rat-deployment/