TRELLIX Advanced Research Center (ARC) researchers have identified a new SideCopy espionage campaign targeting academic institutions and research organisations, as well as defence personnel and government officials across South Asia. SideCopy is described as a suspected Pakistan-nexus threat group that has historically focused on military and diplomatic targets, but is now broadening its operations towards universities and scientific research.
The campaign begins with spear-phishing emails containing ZIP archives. Each archive includes a malicious Windows shortcut disguised as a Word document with a fake PDF icon, alongside an image lure. Opening the shortcut launches the legitimate Windows utility mshta.exe, which retrieves an HTML application from a compromised staging server. The payload then uses .NET deserialisation to load an embedded ne4snapk.dll directly into memory, helping it evade conventional file scanning. The component displays a decoy document, deploys scripts and establishes persistence through the current user’s Windows Run registry key.
A secondary script reconstructs the final payload, loluegnt.dll, in memory. Trellix says the backdoor can capture screenshots and mouse activity, steal saved passwords and clipboard contents, enumerate installed software, terminate processes and run shell commands. Stolen files are sent over an encrypted channel using port 5863, although the malware contains the hardcoded key `NMXIKS09?:709,!~InsYUS`, allowing defenders to decrypt and analyse communications.
Trellix recommends restricting mshta.exe, quarantining ZIP files containing shortcuts, monitoring unusual outbound traffic and checking registry Run entries. The report also identifies `dns.educationportals.biz` and an associated IP address as infrastructure to block.