PULSE NAME
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
WHITE SideCopy AlienVault 2026-05-29 Modified: 2026-05-29
16
IOCs
MEDIUM VOLUME
SideCopy APT, a Pakistan-linked threat group under the Transparent Tribe umbrella, executed a targeted spear phishing campaign against Afghanistan's Ministry of Finance and provincial revenue directorates. The attack begins with a Pashto-language LNK file disguised as a staff directory document, which executes mshta.exe to fetch remote HTA payloads from compromised Afghan education infrastructure. The multi-stage chain deploys obfuscated JavaScript, establishes registry-based persistence mimicking Microsoft Edge, and ultimately delivers XenoRAT 1.8.7 beaconing to bulletproof Bulgarian hosting. The campaign demonstrates precise knowledge of target administrative context, using Dari and Pashto decoy documents listing provincial finance officials with direct contact information. Infrastructure analysis reveals deliberate staging within Afghan government IP space and C2 infrastructure overlapping with previous SideCopy operations.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
XenoRAT
Indicators of Compromise (16)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0b937b7da4602a8aa5346681b13a3466 2026-05-29
FileHash-MD5 14ce728a416b1f13e8645f3f7b860a37 2026-05-29
FileHash-SHA1 c7e18465db47d364bf9b1f56ab0465a649ec6bfb 2026-05-29
FileHash-SHA1 dcac34657f59ac8e99edcc1d1aacc618a5131aa9 2026-05-29
FileHash-SHA256 0019212f25eb04bbb33bb194879c095265db7855d6003bdd777cf0cbb90eb772 2026-05-29
FileHash-SHA256 194b912c242604d6f9a79369f22338c58a13ce0cc2ed280ce505075808bc2f14 2026-05-29
FileHash-SHA256 3b4194bdfe40d94031a94b30397ffd8a4b09d0a4057668e897b8bdcd1703dd01 2026-05-29
FileHash-SHA256 5833917bd137804f5a021d2cb37adfe5c4b7b67dbb06d59c3b9c5cf393835e45 2026-05-29
FileHash-SHA256 8f2d979ef33b2900351c94c7335275a9342c75189e1a901998e90a539e944a1a 2026-05-29
FileHash-SHA256 99127c8c67d90e2776beeb85281f9c68399bf4567b07a6b638d68b760212e88d 2026-05-29
FileHash-SHA256 9ae3d785486022af82ea92e51b26e3f55c1bba88a7be2ad9790f4240e8499d14 2026-05-29
FileHash-SHA256 a63e90ee57a1f213a8fe76ef1a6cff5ae9ed7ebceda258431533825e648c0c67 2026-05-29
FileHash-SHA256 df9173a28c0b0b878c10a53d35cd7ce6f6ed66d207b6b7c4ff723721f1c027ab 2026-05-29
IPv4 103.132.98.224 2026-05-29
IPv4 103.132.98.226 2026-05-29
domain abimj.edu.af 2026-05-29