Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan

dcac34657f59ac8e99edcc1d1aacc618a5131aa9

TLP:CLEAR
Active

SHA-1 Hash

Description

SideCopy APT, a Pakistan-linked threat group under the Transparent Tribe umbrella, executed a targeted spear phishing campaign against Afghanistan's Ministry of Finance and provincial revenue directorates. The attack begins with a Pashto-language LNK file disguised as a staff directory document, which executes mshta.exe to fetch remote HTA payloads from compromised Afghan education infrastructure. The multi-stage chain deploys obfuscated JavaScript, establishes registry-based persistence mimicking Microsoft Edge, and ultimately delivers XenoRAT 1.8.7 beaconing to bulletproof Bulgarian hosting. The campaign demonstrates precise knowledge of target administrative context, using Dari and Pashto decoy documents listing provincial finance officials with direct contact information. Infrastructure analysis reveals deliberate staging within Afghan government IP space and C2 infrastructure overlapping with previous SideCopy operations.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
Pattern Type
STIX
Confidence
75%
Valid From
May 29, 2026 21:09
Total Sightings
0
Added
May 29, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of dcac34657f59ac8e99edcc1d1aacc618a5131aa9

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.