Trellix researchers have documented the Pakistan-linked APT SideCopy — also tracked as TAG-140 and overlapping Transparent Tribe — using spear-phishing lures against Indian academic institutions, an expansion of a group whose historical focus has been Indian defence forces and government officials. The chain delivers a weaponised ZIP containing a Windows shortcut with a spoofed PDF icon and a .docx extension (commskll.docx.lnk); the LNK fetches an obfuscated HTML Application from docsportal[.]in and runs it through mshta.exe, which reflectively loads a DLL payload and self-deletes the HTA once the next stage initialises. That DLL drops three components — a batch script launched from a Windows Registry Run key to re-invoke startT.hta without user interaction, the secondary HTA stage, and a decoy document — and the HTA reconstructs a two-part XAML payload in memory to reflectively load a final DLL, keeping the core payload off disk. The relevance beyond India is the tradecraft pattern: a signed-by-nobody document lure, a living-off-the-land binary, and in-memory staging, which is the same combination the digest reported from Chinese-nexus groups this month. Active since at least 2019, SideCopy was attributed in June 2026 to a campaign against Afghanistan's Ministry of Finance.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-09-23 |
| Source | The Hacker News |
| Reliability | Tier 2 |