logo

SideCopy XenoRAT Malware Attack Targets Afghan Networks

ID: 84dba5f5-18ad-51f9-b661-e0bbbaa40ca0

STIX ID: report--84dba5f5-18ad-51f9-b661-e0bbbaa40ca0

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Ddos

...
...

Operation XENOFISCAL describes a targeted cyber-espionage campaign by the SideCopy/Transparent Tribe cluster that used Pashto-labeled spear-phishing shortcuts to execute fileless XenoRAT via mshta, reconstruct a .NET payload in memory, and establish persistent backdoor access to government workstations (C2 observed at 185.235.137.106); the campaign specifically targeted the Afghan Ministry of Finance and delivered realistic decoy documents to mask compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.