logo

SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry

ID: babc1611-a0b4-5eb9-b63f-55f7fcfd2163

STIX ID: report--babc1611-a0b4-5eb9-b63f-55f7fcfd2163

Feed Name: GBHackers

Threat Score
82/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Eswar

...
...

SideCopy (Transparent Tribe/APT36) conducted a highly targeted spear-phishing campaign against Afghanistan’s Ministry of Finance and all 34 provincial revenue directorates, using a Pashto-labeled LNK in a ZIP to trigger a multi-stage infection chain (mshta -> HTA -> .NET loaders) that executes XenoRAT 1.8.7 in-memory with AMSI bypass and registry persistence; the report includes C2 details (185.235.137.106 via a Frankfurt bulletproof provider), ASN routing, and a table of file hashes as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.