SideCopy Expands Spear‑Phishing Campaign to Indian Academic Institutions Using mshta.exe Abuse
What Happened – Researchers observed the threat actor SideCopy shifting its spear‑phishing operations from Indian government bodies to academic institutions. The campaign delivers malicious emails that invoke mshta.exe to execute scripts, bypassing typical security controls.
Why It Matters for Trust & Control Assurance
- Demonstrates a classic credential‑compromise scenario that continuous control‑assurance programs are built to detect and mitigate.
- Highlights the need for robust security‑awareness training and measurable phishing‑simulation evidence.
- Calls for application‑control policies (e.g., whitelisting or monitoring
mshta.exe) that can be logged as audit‑ready evidence.
Who Is Affected – Universities, colleges, and research labs in India.
Recommended Actions
- Deploy or tighten email‑gateway filtering to block
mshta.exepayloads. - Enforce application‑control or endpoint‑detection policies that log any execution of
mshta.exe. - Conduct targeted phishing‑awareness campaigns and regular simulation exercises for faculty and staff.
- Update incident‑response playbooks to include mshta‑based execution vectors.
Technical Notes – The attack vector is spear‑phishing leveraging the Windows utility mshta.exe to run malicious HTML/JavaScript. No specific CVE is cited; the technique relies on legitimate system functionality. Source: The Hacker News