Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
ID: be345f68-69ff-5d39-a268-13a06485bbef
STIX ID: report--be345f68-69ff-5d39-a268-13a06485bbef
Feed Name: Seqrite Blog
## Executive summary Seqrite Labs documents a targeted spear-phishing campaign (Operation XENOFISCAL) attributed to the SideCopy/APT36 cluster that used a Pashto-labeled LNK inside a ZIP to invoke mshta and fetch an obfuscated HTA/JavaScript payload, staged multiple .NET loader DLLs and in-memory shellcode, and ultimately deployed XenoRAT to provincial Ministry of Finance systems in Afghanistan; the report includes full technical analysis, IOCs (hashes, domains, IPs), infrastructure attribution, and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
