logo

Hackers target Afghan government workers with fake correspondence from senior officials

ID: 1625cf67-6fba-5e56-8e81-cc4aec8507aa

STIX ID: report--1625cf67-6fba-5e56-8e81-cc4aec8507aa

Feed Name: The Record from Recorded Future News

Threat Score
55/100

Date Published: 2026-01-20

Date Updated: 2026-05-01

...
...

Seqrite researchers uncovered a spear-phishing campaign dubbed "Nomad Leopard" targeting Afghan government employees with decoy documents impersonating the prime minister’s office; opening the document installs FalseCub, a data-collection/exfiltration malware. The actor used GitHub as temporary payload hosting and uploaded government-related lure documents to Scribd, with an alias linked to Pakistan; Seqrite assesses the actor as regionally focused with low-to-moderate sophistication and likely an individual operator or small cluster.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.