FalseCub is a data-stealing malware/backdoor observed in phishing campaigns targeting Afghan government employees and officials. Seqrite reported it in an operation tracked as "Nomad Leopard," in which phishing emails masqueraded as official correspondence from Afghanistan’s prime minister’s office and used decoy documents crafted to resemble legitimate government letters sent to ministries and administrative offices. The lures included Pashto-language and other Afghan government-themed administrative content, such as financial-reporting instructions and forged senior-official signatures. When opened, the decoy document delivered FalseCub, which was designed to collect and exfiltrate data from infected computers. The campaign targeted Afghan government institutions, including ministries, administrative offices, and other government employees, and Seqrite warned it might expand beyond Afghanistan. Delivery infrastructure included GitHub repositories used as temporary payload hosting, with files later removed, and shortened links redirecting victims to the GitHub-hosted malware. Seqrite also observed related staging of Afghan- and Taliban-linked legal and administrative documents on Scribd, likely for future lure development, and reuse of an "Afghan Khan" online persona across platforms. Seqrite did not publicly attribute the FalseCub campaign to a specific threat actor, country, or known group, but assessed it as a regionally focused, low-to-moderate sophistication operation tracked as "Nomad Leopard."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A data-stealing malware strain delivered via phishing emails targeting Afghan government employees.
FalseCub is a malware strain delivered via phishing decoy documents that is designed to collect and exfiltrate data from infected computers. In this campaign, the payload was temporarily hosted on GitHub and delivered via a shortened link redirecting victims to the GitHub repository.
Backdoor delivered via spear-phishing using decoy administrative documents (as described in Operation Nomad Leopard targeting Afghanistan government entities).
A backdoor delivered via spear-phishing using decoy administrative documents, providing unauthorized access/persistence on victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.