At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | SideCopy (suspected Pakistan-nexus threat group) |
| Activity Type | Spear-phishing, living-off-the-land execution, cyberespionage |
| Targets or Victims | Academic institutions, defense personnel, and government officials |
| Scale | Multiple targeted research and educational organizations across South Asia |
| Jurisdiction / Status | Active suspected state-sponsored espionage group; uncharged |
| Source | Trellix Advanced Research Center (ARC) |
Executive Summary
Trellix ARC researchers uncovered a new offensive wave driven by the SideCopy APT campaign. The attackers expanded their operations beyond military personnel to target universities and research facilities. Consequently, the group relies on deceptive shortcut files and built-in Windows utilities to deploy custom backdoors without touching the disk.
What Happened
The attack begins with targeted spear-phishing emails carrying weaponized ZIP archives. Inside each archive, victims find a deceptive shortcut file alongside an image lure. This shortcut mimics a Microsoft Word document but uses a fake PDF icon.
When a user opens the shortcut, Windows executes the built-in mshta.exe utility. The program immediately fetches an HTML application file from a compromised staging server. Specifically, the script pulls this payload from an external web domain.
Next, the downloaded script runs a .NET deserialization routine directly in memory. As Trellix ARC noted in its technical report, “The HTA file contains an embedded ne4snapk.dll, and during execution the embedded DLL file is loaded into mshta.exe through a .NET deserialization attack.” This fileless method bypasses conventional file-scanning engines.
The dropped DLL acts as a staging component on the victim host. It extracts three embedded components from internal compressed archives. First, it displays a decoy document discussing business writing skills to mislead the victim. Second, it drops a secondary script to coordinate subsequent tasks. Third, it writes a batch script to maintain long-term execution.
To maintain survival across system reboots, the batch file updates the Windows Registry. It creates a registry entry under the current user Run key. Consequently, the operating system executes the hidden script in the background every time the machine restarts.

Memory Execution and Backdoor Features
The secondary script reconstructs an executable payload directly inside volatile system memory. It uses deprecated .NET serialization classes to bypass security monitors. Then, it uses runtime reflection methods to load the final trojan library, identified as loluegnt.dll.
Once active, the trojan provides the operators with extensive remote administration commands. The malware captures desktop screenshots, records mouse clicks, and steals saved user passwords. Furthermore, the implant grabs clipboard text and lists installed software on the infected computer. It also allows operators to terminate running processes and execute arbitrary shell commands.
The malware transmits stolen files across an encrypted network channel on port 5863. However, the threat actors hardcoded an encryption key directly inside the program code. As Trellix ARC discovered, “the discovery of a hardcoded cryptographic key (NMXIKS09?:709,!~InsYUS) allows defenders to decrypt and analyze C2 communications.”
Who Is Behind It
Security researchers attribute this campaign to SideCopy with high confidence. The group emerged around 2020 as a suspected Pakistan-nexus espionage cluster. Independent research confirms that SideCopy frequently mimics another regional group named Sidewinder. Security vendor Seqrite also tracks these persistent regional intrusions.
Historically, the adversary focused almost exclusively on military and diplomatic organizations in India. Trellix ARC highlighted this operational shift in its analysis. The researchers observed, “While the primary objective of advanced persistent threat (APT) groups like SideCopy has historically been the surveillance and exfiltration of sensitive data from government officials and high-ranking personnel, their strategic scope has recently broadened to include academic institutions.” This transition indicates an expanding interest in university research and scientific intelligence.
Impact and Scale
This campaign highlights a serious threat to academic environments and government agencies. By exploiting trusted administrative binaries like mshta.exe, the attackers avoid triggering standard antivirus alarms. In addition, the SideCopy APT campaign malware uses memory-only execution to defeat static file scanners.
Higher education networks often feature open IT environments with mixed security controls. Therefore, academic personnel remain prime targets for espionage actors seeking intellectual property. In addition, compromised university systems can serve as staging grounds for deeper intrusions into partner defense networks.
What Comes Next and Defense Guidance
Organizations must apply strict endpoint restrictions to protect against these stealthy intrusions. Administrators should block or restrict execution permissions for mshta.exe across employee workstations. Because the malware relies on deceptive shortcuts, email filters must quarantine inbound ZIP archives containing shortcut files.
Network defenders should also monitor network perimeters for unusual outbound connections over non-standard ports. Specifically, security teams should block traffic targeting the malicious domain dns.educationportals.biz and its associated IP address. Regular threat hunting in the Windows registry will help detect rogue persistence entries early.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!