logo

Pakistan Spies on Afghan Finance Ministry With Xeno RAT

ID: 7c6b4e2d-3177-58c0-b806-c253208a1a9a

STIX ID: report--7c6b4e2d-3177-58c0-b806-c253208a1a9a

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2026-06-04

Date Updated: 2026-06-15

Author: Nate Nelson

...
...

A Pakistani-linked APT known as SideCopy targeted Afghanistan's Ministry of Finance and provincial employees with spear-phishing lures localized in Pashto. The attackers used ZIP archives containing LNK files that invoked mshta to fetch and decode HTA payloads in memory, installed loaders, established registry persistence disguised as Microsoft Edge, and deployed a customized Xeno RAT with hardcoded C2 infrastructure hosted through a bulletproof service and a compromised Afghan government domain to blend malicious traffic with legitimate state traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.