Researchers reported a targeted phishing operation against Afghan government employees that impersonates official correspondence from the prime minister’s office and other ministries to trick recipients into opening a weaponized decoy document. The lure is designed to look like legitimate administrative/financial reporting instructions and includes forged signatures; once opened, it deploys FalseCub malware intended to collect and exfiltrate data from infected systems. The activity shows evidence of careful target research, including the collection of Afghan legal and administrative materials (e.g., ministry communications and related documents) that could be reused as future lures.
The operation abused GitHub as temporary payload hosting, with a newly created account used to distribute malware before content was removed, and investigators linked the operator’s online persona (e.g., alias “Afghan Khan” / user afghanking777000) across platforms such as Pinterest and Dailymotion. Telemetry cited by researchers also pointed to Pakistan-linked artifacts (e.g., link creation/upload location) associated with the shortened URL redirecting victims to the GitHub-hosted payload. Reporting described the actor as Nomad Leopard (per SEQRITE Labs’ tracking) but did not provide a definitive attribution to a known state or established APT group.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On January 20, 2026, Seqrite publicly disclosed the campaign, linking the infrastructure and reused online persona to a regionally focused, low-to-moderate sophistication actor it named 'Nomad Leopard.' The company noted OPSEC mistakes such as persona reuse across platforms but did not attribute the activity to a specific country or known threat group.
Researchers found the threat actor had uploaded multiple Afghan government-, legal-, and Taliban-themed documents under the 'Afghan Khan' persona on platforms including Scribd, Pinterest, and Dailymotion. Seqrite assessed these materials were likely prepared for future phishing activity and possible expansion beyond current Afghan government targeting.
In late December 2025, the operators used a newly created GitHub account to host the malicious payloads used in the campaign, blending delivery into legitimate traffic. The infection chain used an ISO attachment containing a malicious LNK that launched a hidden executable disguised as an image file, ultimately delivering the FalseCub information stealer.
Seqrite said the operation was first detected in December 2025 and targeted Afghan ministry and administrative office employees with emails masquerading as official correspondence from Afghanistan’s prime minister’s office. The lures used government-style financial reporting instructions and forged senior-official signatures to entice recipients into opening the files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.