A Pakistan-linked espionage group tracked as SideCopy targeted Afghanistan’s Ministry of Finance, provincial finance and revenue offices, and other Pashto-speaking officials with spear-phishing emails that delivered the open-source remote access trojan XenoRAT. Seqrite said the campaign, dubbed Operation XENOFISCAL, used Pashto-language seminar-themed lures and ZIP archives containing a malicious shortcut file disguised as an internal government document; one decoy was a genuine Ministry of Finance staff directory covering all 34 provinces, suggesting prior reconnaissance or earlier compromise of Afghan government networks.
The infection chain abused mshta.exe, obfuscated JavaScript, .NET loaders, and reflective loading to establish a largely fileless foothold, then maintained persistence through Windows Registry changes and a scheduled task. Researchers said the attackers used a compromised Afghan education domain and other Afghan government-hosted infrastructure to make traffic appear legitimate, while separating payload delivery from command-and-control servers hosted in Europe, including Frankfurt, to reduce detection. Seqrite attributed the activity to SideCopy with medium-to-high confidence and linked the operation to the group’s broader history of targeting South Asian government entities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Seqrite attributed the Afghanistan-focused operation, dubbed Operation XENOFISCAL, to the Pakistan-linked SideCopy threat group with medium-to-high confidence. The assessment cited tailored Pashto lures, target selection, and infrastructure choices consistent with the actor’s tradecraft.
Seqrite identified a cyberespionage campaign targeting Afghanistan’s Ministry of Finance, provincial finance and revenue offices, and other Pashto-speaking government officials. The attackers used Pashto-language phishing lures and malicious archives to deploy XenoRAT through a multi-stage infection chain.
Seqrite released detections and a detailed set of indicators of compromise for the SideCopy campaign targeting Afghan finance entities. The publication was intended to support threat hunting and remediation by defenders.
Kaspersky said the latest wave of attacks against Russian organizations began in January 2026. This wave used Ravage following phishing-based initial access and multi-stage malware delivery.
The Ravage penetration-testing framework used in the Russian-targeting campaign was released on GitHub in September 2025. Kaspersky later observed it being repurposed in real-world intrusions.
Kaspersky reported that a previously unknown hacking group has been targeting Russian organizations since at least 2024. Victims included maritime universities, energy facilities, diplomatic missions, government agencies, and financial institutions.
Seqrite reported that the Pakistan-linked SideCopy group had been conducting an espionage campaign against Afghanistan’s government finance sector since at least May 2025. The operation used Pashto-language spear-phishing lures and a customized Xeno RAT in a sustained effort against finance-related government targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcexakep.ru
Open sourcetherecord.media
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.