logo

Afghan Government Compromise: Browser Beware

ID: 75a2eeed-0b97-5e35-9680-2f53bbcff596

STIX ID: report--75a2eeed-0b97-5e35-9680-2f53bbcff596

Feed Name: Volexity Blog

Threat Score
75/100

Date Published: 2015-06-12

Date Updated: 2026-05-01

...
...

The report documents a strategic web compromise of the Afghan government CDN (cdn.afghanistan.af) in which attackers appended obfuscated JavaScript (using Dean Edwards Packer/base62) to jquery-1.4.2.min.js to perform a document.write that loads additional malicious JavaScript from 176.58.101.24 (Linode). The compromise affected multiple government websites, appears selectively targeted (whitelisting observed), and is attributed to APT-like actors; network indicators and ASN information are provided for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.