Threats · 103 days ago
This campaign works because it speaks the target’s language. A Pashto filename inside a ZIP makes the lure look native to Afghan finance staff, so a shortcut that should look routine instead opens the door to operator access on government machines.
Seqrite Labs says SideCopy, which is linked to Pakistan and Transparent Tribe, used that tactic in Operation XENOFISCAL against Afghanistan’s Ministry of Finance and provincial revenue and finance directorates. The activity delivered Xeno RAT, a tool built for spying and control, including keystrokes, screenshots, clipboard data, proxy tunneling, and persistence.
For the affected finance bodies, the issue is not a single infected endpoint. It is access into sensitive government workflows, where a convincing local-language lure can turn ordinary paperwork into a reliable entry point.
3 sources covering this story
Pakistan Spies on Afghan Finance Ministry With Xeno RAT
Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
SideCopy targeted Afghanistan's Finance Ministry with Xeno RAT via Pashto phishing lures, enabling espionage and system compromise.
The Record from Recorded Future
Afghan finance officials targeted by suspected Pakistani cyberespionage campaign
A suspected Pakistan-linked hacking group has targeted Afghanistan's Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found.
Part of the PlainSec briefing for 2026-06-04