Pakistan Spies on Afghan Finance Ministry With Xeno RAT
ID: 7c6b4e2d-3177-58c0-b806-c253208a1a9a
STIX ID: report--7c6b4e2d-3177-58c0-b806-c253208a1a9a
Feed Name: Dark Reading
A Pakistani-linked APT known as SideCopy targeted Afghanistan's Ministry of Finance and provincial employees with spear-phishing lures localized in Pashto. The attackers used ZIP archives containing LNK files that invoked mshta to fetch and decode HTA payloads in memory, installed loaders, established registry persistence disguised as Microsoft Edge, and deployed a customized Xeno RAT with hardcoded C2 infrastructure hosted through a bulletproof service and a compromised Afghan government domain to blend malicious traffic with legitimate state traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
