Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

June 8, 2026

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

June 8, 2026

OpenAI Unveils ChatGPT Account Security Controls

June 8, 2026
Facebook X (Twitter) Instagram
Monday, June 8
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
News

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

Team-CWDBy Team-CWDJune 8, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan’s Ministry of Finance with an open-source remote access trojan called Xeno RAT.

“The campaign opens with a spear phishing delivery – a ZIP archive containing a malicious LNK file bearing a carefully crafted Pashto-language filename,” Seqrite Labs researcher Dixit Panchal said in a technical breakdown of the activity.

Also targeted as part of the campaign are provincial revenue and finance directorates, Pashto-speaking government officials, and provincial-level government employees. The campaign has been codenamed Operation XENOFISCAL.

The choice of Pashto for the lure file is a deliberate choice on the part of the attacker, as it’s the main language spoken in the Afghan government circles. This aspect reflects the attacker’s familiarity with the target environment.

SideCopy is the name given to a Pakistan-linked threat group operating under the broader Transparent Tribe (aka APT36) umbrella, using a wide range of malware families to steal sensitive data from compromised hosts. In April 2025, the adversary was attributed to a set of attacks targeting various sectors in India with Xeno RAT, Spark RAT, and CurlBack RAT.

Viewed in that light, the latest campaign is a continuation of a broader cluster of malicious cyber activity aimed at South Asian entities.

Once executed, the Windows Shortcut (LNK) file leverages “mshta.exe” to fetch a remote HTML Application (HTA) from a compromised Afghan education domain, leading to the execution of obfuscated JavaScript in memory. The malware also establishes Registry-based persistence by mimicking Microsoft Edge, while dropping Xeno RAT 1.8.7 and a decoy document as a distraction mechanism by means of a DLL-based loader.

Xeno RAT is designed to connect with a remote server over TCP to handle commands sent by the operator. The malware is equipped to load and execute external DLL modules, transmit data to the server, launch the malware via a scheduled task, retrieve antivirus information, support SOCKS5 proxy-based network tunneling, perform file operations, log keystrokes, take screenshots, monitor the clipboard, track webcam/microphone, delete persistence methods, and uninstall itself from the host.

The disclosure comes as details have emerged of a targeted phishing operation leveraging weaponized Linux .desktop files to target the Indian military infrastructure using contract-related lures associated with Indian-armored vehicle procurement operations. The campaign is assessed to be the work of Transparent Tribe.

“The campaign appears to target individuals connected to Indian military and defense infrastructure ecosystems using WhatsApp-based social engineering and staged shell payload delivery,” security researcher R.D. Tarun said in a report published last month.

“Once executed, the malicious .desktop launcher initiates a heavily obfuscated shell-based infection chain involving staged payload retrieval, inline decoding routines, and deployment of a Golang-based ELF implant tracked in this report as DeskRAT.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleOpenAI Unveils ChatGPT Account Security Controls
Next Article North Korean Hackers Use Fake Coding Tasks to Steal Crypto
Team-CWD
  • Website

Related Posts

News

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

June 8, 2026
News

OpenAI Unveils ChatGPT Account Security Controls

June 8, 2026
News

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

June 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Chronology of a Skype attack

February 5, 2026

Here’s what you should know

February 6, 2026

How the always-on generation can level up their cybersecurity game

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.