Nomad Leopard is a regionally focused, low-to-moderate sophistication cyber-espionage/phishing threat actor tracked by SEQRITE/Seqrite. The actor has targeted Afghan government employees by sending phishing emails disguised as official correspondence/ministerial notices from Afghanistan’s prime minister’s office and other government entities. Lures include decoy documents formatted like legitimate government letters (including religious greetings, financial-reporting instructions, and forged senior-official signatures) and the actor has staged additional Afghan- and Taliban-linked legal/administrative documents (e.g., Afghan government directives, Afghanistan Ministry of Defense communications, and U.S. asylum/human-rights documents related to Afghanistan) on Scribd, assessed as potential future phishing lures. The observed infection chain includes an ISO attachment containing a malicious LNK that, upon user interaction, launches a hidden payload; the payload includes an executable renamed to appear as a benign image file. The delivered malware is dubbed “FalseCub,” assessed to collect and exfiltrate data from infected systems. For payload distribution, Nomad Leopard temporarily hosted malicious files in GitHub repositories (using an account created in late December and later removing the files), leveraging GitHub to blend with legitimate traffic. The actor repeatedly reused an online persona/alias “Afghan Khan,” including a GitHub user “afghanking777000,” also seen on platforms such as Pinterest and Dailymotion—an OPSEC weakness SEQRITE assessed as consistent with an individual operator or small cluster rather than a mature state-sponsored APT. Some indicators (e.g., at least one “Afghan Khan” account and a shortened link upload redirecting to the GitHub repository) were linked to Pakistan, but SEQRITE did not attribute the activity to a specific country or known group. SEQRITE warned the campaign may expand beyond Afghanistan.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Regionally focused phishing campaign targeting Afghan government employees using decoy government letters to deliver the FalseCub infostealer; uses GitHub for temporary payload hosting and leverages legal/government documents (e.g., Afghan directives, Ministry of Defense communications, U.S. asylum/human-rights documents) as lure material.
Cyber-espionage campaign targeting Afghan government ministries and administrative offices via phishing emails with official-looking lure documents. Delivery uses ISO attachments containing malicious LNK shortcuts that execute a hidden payload (an executable renamed to resemble an image). The actor abuses GitHub repositories to host/distribute payloads and blend into legitimate traffic; OPSEC mistakes (persona reuse across platforms) suggest a small cluster/individual with low-to-moderate sophistication.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.