PULSE NAME
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
WHITE SideCopy AlienVault 2026-05-29 Modified: 2026-05-29
16
IOCs
MEDIUM VOLUME
SideCopy APT, a Pakistan-linked threat group under the Transparent Tribe umbrella, executed a targeted spear phishing campaign against Afghanistan's Ministry of Finance and provincial revenue directorates. The attack begins with a Pashto-language LNK file disguised as a staff directory document, which executes mshta.exe to fetch remote HTA payloads from compromised Afghan education infrastructure. The multi-stage chain deploys obfuscated JavaScript, establishes registry-based persistence mimicking Microsoft Edge, and ultimately delivers XenoRAT 1.8.7 beaconing to bulletproof Bulgarian hosting. The campaign demonstrates precise knowledge of target administrative context, using Dari and Pashto decoy documents listing provincial finance officials with direct contact information. Infrastructure analysis reveals deliberate staging within Afghan government IP space and C2 infrastructure overlapping with previous SideCopy operations.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
XenoRAT
Indicators of Compromise (2 / 16 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 c7e18465db47d364bf9b1f56ab0465a649ec6bfb 2026-05-29
FileHash-SHA1 dcac34657f59ac8e99edcc1d1aacc618a5131aa9 2026-05-29