Pashto Lures Mask Espionage in Afghan Finance Campaign

This campaign works because it speaks the target’s language. A Pashto filename inside a ZIP makes the lure look native to Afghan finance staff, so a shortcut that should look routine instead opens the door to operator access on government machines. Seqrite Labs says SideCopy, which is linked to Pakistan and Transparent Tribe, used that tactic in Operation XENOFISCAL against Afghanistan’s Ministry of Finance and provincial revenue and finance directorates. The activity delivered Xeno RAT, a tool built for spying and control, including keystrokes, screenshots, clipboard data, proxy tunneling, and persistence. For the affected finance bodies, the issue is not a single infected endpoint. It is access into sensitive government workflows, where a convincing local-language lure can turn ordinary paperwork into a reliable entry point.

Part of the PlainSec briefing for 2026-06-04

Sources