Photo: markusspiske / Pixabay
English
On 22 September 2026 the security firm Trellix reported that SideCopy, a hacking group tracked to Pakistan, was sending booby-trapped files to Indian academic institutions. SideCopy and the related Transparent Tribe have targeted soldiers and government staff since at least 2019, and their bait has followed India's own headlines: Kavach, Pahalgam, Operation Sindoor.
On 22 September 2026 the security firm Trellix described a file that had been sent to people at Indian academic institutions. It comes inside a ZIP archive and is called commskll.docx.lnk. The icon is a PDF’s and the name ends in the Word extension .docx, but the file is a Windows shortcut, and opening it sets off a chain of scripts that ends with a remote-control program running on the victim’s computer. While that happens, a harmless decoy called commskl.docx opens on screen.
Trellix tied the campaign to SideCopy, a hacking group that security vendors track to Pakistan and that has been active since at least 2019, according to The Hacker News’s account of the report. Until now it mostly went after Indian defence forces and government officials. The Indian government has not formally attributed these campaigns, and we found no such attribution, so every link to Pakistan in this article is a named vendor’s assessment.
A shortcut dressed as a PDF
Trellix researchers Boggavarapu R S S Srinivas Gupta and Ravishankar N C traced the chain step by step. The shortcut reaches out to a server at docsportal[.]in and uses mshta.exe, a program that ships with Windows and runs a type of script file called an HTA. Both are part of the operating system, so nothing has to be downloaded to use them.
The scripts include a batch file named appT.bat and a second stage called startT.hta. They decode their payload in steps and load a library file, ioluegnt.dll, straight into the computer’s memory. The last step installs ReverseRAT.
The code is layered to resist inspection. Trellix found that the HTA files are obfuscated with several rounds of scrambling that have to be undone in order, that the payloads are encoded in Base64 (a way of writing binary data as plain text), and that the final library is loaded through a feature of the .NET framework called deserialisation. The malware also carries a hard-coded encryption key. We are not reproducing it, because it adds nothing for a reader.
A RAT, in the trade’s shorthand, is a remote access trojan. ReverseRAT collects system details and a list of installed software, takes screenshots, steals passwords and clipboard contents, runs files and commands, opens a shell for the operator, and sets itself up to survive a restart through the Windows Registry. It reports to dns.educationportals[.]biz, which resolves to 45.61.157[.]22, and sends stolen data out through port 5863. We have defanged those addresses with brackets so nobody can click them by accident.
Trellix summed up the shift in a line the Hacker News quoted: “While their historical focus has been on Indian government entities, their recent pivot toward academic institutions highlights an expanding set of strategic priorities.”
Copying a rival’s homework
Cisco Talos gave SideCopy its name. In a report published on 7 July 2021, researchers Asheer Malhotra and Justin Thattil wrote: “SideCopy is an APT group that mimics the Sidewinder APT’s infection chains to deliver its own set of malware.” APT stands for advanced persistent threat, the industry’s label for a well-resourced group that keeps coming back. SideWinder is another hacking group, and SideCopy’s copying of its methods gave it the name.
Talos listed a toolkit that was already large in 2021: CetaRAT, Allakore and njRAT, plus four custom programs it called DetaRAT, ReverseRAT, MargulasRAT and ActionRAT. The lures were built to be recognised by their readers. Talos described “decoys posing as operational documents belonging to the military and think tanks” and “honeytrap-based infections,” the second phrase meaning bait that plays on a target’s personal interests. Both kinds of bait were aimed at Indian government personnel.
The Hacker News report on the September 2026 campaign says SideCopy is also tracked as TAG-140 and overlaps with Transparent Tribe, also known as APT36, a group Check Point calls “a Pakistan-based threat actor notorious for persistently targeting Indian government organizations, diplomatic personnel, and military facilities.” The two clusters overlap, which is why vendors report on them together.
Malware that checks the clock first
In its report of 4 November 2024, Check Point Research followed a program called ElizaRAT, which it said was first publicly disclosed in September 2023. Check Point described it as a tool of Transparent Tribe and reported “multiple likely successful campaigns” against high-profile Indian targets in 2024.
Every sample Check Point analysed does one thing before it runs: it checks whether the computer’s time zone is set to “India Standard Time.” A machine set to any other zone is left alone, so a researcher testing the file on a laptop set to London time sees the file do nothing. That single test narrows the victim pool to computers configured for India.
The operators also changed how the malware talks to them. Check Point described the “systematic abuse of cloud-based services” for control traffic: Telegram in early variants, then Slack, then Google cloud storage. A variant Check Point called Circle, compiled in January 2024, dropped the cloud services for rented servers and came with a dropper that lowered its detection rate.
One thing in the code ties the variants together. The name “Apolo Jones” turns up across Check Point’s samples, in PDF metadata, in function names, and in zip passwords such as “ApoloJones2024.” Check Point used it to link all the variants to Transparent Tribe.
The same report introduced ApoloStealer, a companion program that hunts for Office documents, PDFs, images and archives and logs what it finds in a small database before sending the files out.
Going after India’s own operating system
On 25 August 2025 The Hacker News reported, from research by the firm CYFIRMA, that Transparent Tribe had started aiming at Linux machines. The bait was a file called Meeting_Ltr_ID1543ops.pdf.desktop. A .desktop file is a Linux launcher, and this one wore a PDF’s name. Opened on the target machine, it fetched hex-encoded payloads from a server, set up a scheduled job to stay installed, and called home to modgovindia[.]space:4000.
Indian government offices running BOSS Linux, a distribution they use, were the intended victims. Payloads included the Poseidon backdoor and MeshAgent, a remote management tool. A program called the Sindoor Dropper, a compressed Go binary, delivered them while showing a decoy PDF. The report came about three months after Operation Sindoor, and the dropper carries the operation’s name. The report quotes CYFIRMA on the point of the exercise: the group’s ability to “customize its delivery mechanisms according to the victim’s operating environment” raises its chances of success.
Kavach, the two-factor authentication tool that government agencies use, had been a target before. The same coverage recalled an older campaign built around it, and The Hacker News dates that tactic to early 2022, when the groups went after the login details of government staff through fake Kavach downloads.
A flying club and a fake ThePrint
On 2 January 2026 The Hacker News reported another Transparent Tribe campaign against Indian governmental, academic and strategic bodies. The bait was a shortcut named NCERT-Whatsapp-Advisory.pdf.lnk, posing as a government advisory, with NCERT, the National Council of Educational Research and Training, in its name. Opening it ran a hidden command that fetched an installer from aeroclubofindia.co[.]in, the real website of the Aero Club of India, which the attackers had compromised.
Once installed, the malware set itself to start again through Registry changes, scheduled tasks and shortcut files in the Windows startup folder. The control server, dns.wmiprovider[.]com, was registered in mid-April 2025. Its web endpoints were spelled backwards to slip past scanners that look for words like register and heartbeat: /retsiger, /taebtraeh, /dnammoc_teg.
The first address a victim’s computer contacted was a real Indian organisation’s domain. The September 2026 campaign borrowed the names of newsrooms instead.
Commands only on weekdays
Zscaler’s ThreatLabz team named the September campaign Operation RapidRust, and The Hacker News carried the report on 18 September 2026. The target list was government and defence bodies in India and Afghanistan. Zscaler counted four previously undocumented tools: RUSTYSHADE, a backdoor written in the Rust programming language, RUSTYMOVE, which spreads through USB drives, and two file thieves, PSNATCH for Windows and BASHNATCH for Linux, that grab documents, images and archives modified within the last three months.
RUSTYSHADE can take screenshots, capture the webcam and work with files on the machine. It takes its orders through private repositories on GitHub, the code-sharing site that programmers use every day. The operators also registered lookalike domains for two Indian news outlets, theprints[.]org and indiatodays[.]org, and used them to host PowerShell scripts.
Zscaler’s report appeared four days before Trellix’s. It also described a work schedule. A significant share of the activity fell between 20 August and 1 September 2026, with commands issued “only between 4 a.m. and 11 a.m. UTC and only on weekdays.” In India that window runs from 9:30 am to 4:30 pm.
Pahalgam, Sindoor and the lure calendar
On 22 April 2025 gunmen killed 26 people at Pahalgam, and on 7 May India launched Operation Sindoor against targets in Pakistan. The bait followed. The Indian security firm Seqrite, in a report dated 23 May 2025, found APT36 and SideCopy sending Pahalgam-themed files and registering domains such as pahalgamattack[.]com, operationsindoor2025[.]in and sindoor[.]live.
Seqrite said the spoofed domains were built to impersonate Indian government and defence bodies. It said APT36 had moved from older Poseidon loaders to Ares RAT, a modular tool that logs keystrokes, captures screens, handles files, steals credentials and runs remote commands, and that it also used Crimson RAT, a second remote access program that called back to a server at 167.86.97[.]58 on port 17854. The firm listed defence, government IT, healthcare, telecom and education among the sectors that faced intrusion attempts.
The security firm CloudSEK reported the same pattern. After Pahalgam, it said, APT36 sent phishing emails disguised as government documents to Indian government and defence networks, carrying Crimson RAT. In both reports the lure is a news event, followed by a file named after it.
Laid out in order, the file names in this article read like a calendar. Talos found decoys built from military and think-tank documents in July 2021, and the bait of early 2022 was a fake Kavach download. April and May 2025 brought Pahalgam and Sindoor attachments, and August a Linux shortcut called Meeting_Ltr_ID1543ops.pdf.desktop. An NCERT advisory followed in January 2026, a lookalike of a news site in September, and then the file called commskll.docx.lnk, which Trellix described on 22 September.
Fifteen lakh attacks, 150 successes
Maharashtra Cyber, the Maharashtra state’s cyber agency, produced a report titled “Road of Sindoor.” Its headline figure, as the Tribune reported it on 12 May 2025, was about 15 lakh (1.5 million) cyber attacks on Indian websites, of which 150 succeeded. Two numbers have to be kept apart here. The 15 lakh counts attempts and scans that reached Indian systems. The 150 is the number that got in.
Seven groups were named in the report: APT36, Pakistan Cyber Force, Team Insane PK, Mysterious Bangladesh, Indo Hacks Sec, Cyber Group HOAX 1337 and National Cyber Crew. It listed malware campaigns, distributed denial-of-service floods (which knock a site offline by overwhelming it with traffic), GPS spoofing and website defacement. Officials said that although hostilities between India and Pakistan had ceased, the attacks continued to come from Pakistan, Bangladesh, Indonesia, Morocco and Middle Eastern countries.
The confirmed successes the Tribune listed were small. The website of the Kulgaon Badlapur Municipal Council was defaced, and so was that of the Defence Nursing College in Jalandhar. Alleged data theft from an airport and from telecom companies appeared on the same list, and the Tribune labelled it alleged.
Yashasvi Yadav, Additional Director General of Police at Maharashtra Cyber, denied online claims that hackers had breached Mumbai’s airport or the Election Commission’s website. The report also said officials found and removed more than 5,000 pieces of misinformation, among them invented stories of attacks on the power grid and on a BrahMos missile facility. Of 80 flagged cases, 35 were taken down.
The noise, and what it hid
Seqrite counted “35+ hacktivist groups involved, 7 newly emerged,” and “650+ confirmed DDoS/defacement events” between 7 and 10 May 2025. A hacktivist is a hacker working for a political cause, with no need to be on any government’s payroll. Seqrite’s 650 and Maharashtra Cyber’s 15 lakh measure different things, one a count of confirmed denial-of-service and defacement events over four days, the other a total of attempted attacks, and the two numbers should not be added together.
CloudSEK went through the claims. Hacktivist groups including Nation Of Saviors and KAL EGY 319 had claimed major breaches, among them 247 GB of data taken from the National Informatics Centre. The proof they posted came to 1.5 GB of publicly available media files. Data said to come from the Andhra Pradesh High Court was mainly public case metadata. Infosecurity Magazine summed up CloudSEK’s findings on 12 May 2025: “Defaced websites were often restored within minutes, leaked data turned out to be public or recycled and Distributed Denial of Service (DDoS) attacks caused negligible downtime.”
Some of the hacktivists did real damage. Mysterious Team Bangladesh, which appears in the Maharashtra list as Mysterious Bangladesh, was profiled by Group-IB in 2023 as a hacktivist group driven by religious and political motives, whose main targets were organisations in India and Israel. Group-IB credited it with more than 750 denial-of-service campaigns and 78 defacements since June 2022, and with a December 2022 breach at India’s Central Board of Higher Education that exposed personal information.
CloudSEK separated the two kinds of activity. Its report treats the APT36 phishing emails as the intelligence threat. Infosecurity Magazine described what Crimson RAT does with a victim’s machine: “Once the malware has collected sensitive data, such as screenshots, files or system information, it sends this data back to the C2 server for further analysis by the attackers.” C2 means command and control, the attackers’ server.
Who names Pakistan
Sameer Patil, who directs the Centre for Security, Strategy and Technology at the Observer Research Foundation, wrote in May 2026 that the Maharashtra report was one of the rare instances of an Indian government agency naming a country as the perpetrator. He added that the attacks were routed through third countries such as Bangladesh, Morocco and Indonesia to obscure where they began. For the espionage campaigns described above, the attributions we found come from security vendors, among them Trellix, Check Point, Zscaler, CYFIRMA, Talos and the Indian firm Seqrite, who describe the groups as Pakistan-based, Pakistan-aligned or of Pakistani origin. Check Point calls APT36 Pakistan-based, Zscaler calls it a Pakistan-nexus actor, and CYFIRMA assesses Transparent Tribe to be of Pakistani origin. Those are findings of private firms, each from its own data, and none carries the weight of a government statement.
The spying runs in more than one direction. In a report covered by The Record on 5 June 2025, the firm Proofpoint assessed that it is “highly likely” that a group it calls TA397, also known as Bitter, spies on behalf of India’s government. Proofpoint said Bitter went after diplomatic and government bodies linked to China and Pakistan, among other neighbours, between October 2024 and April 2025.
Patil’s own conclusion, in his piece for ORF on 7 May 2026, one year after Sindoor, was that “India’s cyber defences can hold the line, but deterrence demands more.” The full sentence goes on to name what he thinks is missing: “a proactive posture, credible attribution, and a long-overdue national strategy.” He credited the Computer Emergency Response Team of India (CERT-In) with advisories during the operation that helped prevent large-scale disruption, and he cited the same 150 successes out of 1.5 million attacks that Maharashtra Cyber reported.
India’s National Cyber Security Strategy, which Patil notes has been in the works since 2020, was still unreleased when his article appeared on 7 May 2026.
Sources & further reading
- Ravie Lakshmanan, SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing, The Hacker News, 22 September 2026
- Asheer Malhotra and Justin Thattil, InSideCopy: How this APT continues to evolve its arsenal, Cisco Talos, 7 July 2021
- Cloudy With a Chance of RATs: Unveiling APT36 and the Evolution of ElizaRAT, Check Point Research, 4 November 2024
- Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing, The Hacker News, 25 August 2025
- Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia, The Hacker News, 2 January 2026
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2, The Hacker News, 18 September 2026
- Operation Sindoor: Anatomy of a High-Stakes Cyber Siege, Seqrite Labs, 23 May 2025
- Pakistan-allied hackers launched 15 lakh cyber attacks on Indian websites, only 150 successful, The Tribune, 12 May 2025
- Hacktivist Attacks on India Overstated Amid APT36 Espionage Threat, Infosecurity Magazine, 12 May 2025
- Sameer Patil, Operation Sindoor at One: Taking Stock of India's Cyber Preparedness, Observer Research Foundation, 7 May 2026
- Mysterious Team Bangladesh targeting India, The Hacker News (Group-IB research), 3 August 2023
- New evidence links long-running hacking group to Indian government, The Record, 5 June 2025
Researched and written with the help of AI tools and edited for accuracy. Provided for general information and discussion only, not professional advice. See our editorial standards and disclaimer. Spotted an error? Tell us.
Enjoyed this? Get the next one.
One good read at a time, straight to your inbox. No spam, unsubscribe anytime.