logo

Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan

ID: be345f68-69ff-5d39-a268-13a06485bbef

STIX ID: report--be345f68-69ff-5d39-a268-13a06485bbef

Feed Name: Seqrite Blog

Threat Score
90/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Dixit Panchal

...
...

## Executive summary Seqrite Labs documents a targeted spear-phishing campaign (Operation XENOFISCAL) attributed to the SideCopy/APT36 cluster that used a Pashto-labeled LNK inside a ZIP to invoke mshta and fetch an obfuscated HTA/JavaScript payload, staged multiple .NET loader DLLs and in-memory shellcode, and ultimately deployed XenoRAT to provincial Ministry of Finance systems in Afghanistan; the report includes full technical analysis, IOCs (hashes, domains, IPs), infrastructure attribution, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.