Skip to content
SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry

SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry

Gbhackers May 30, 2026

Pakistan-linked threat actor SideCopy has launched a highly targeted spear-phishing campaign against Afghanistan’s Ministry of Finance (MoF). The operation surgically targets all 34 provincial revenue directorates, operating under the broader Transparent Tribe (APT36) umbrella.

According to threat intelligence reports from Seqrite, the campaign culminates in the deployment of a customized XenoRAT 1.8.7 implant that beacons to bulletproof European infrastructure.

The attack sequence opens with a ZIP archive containing a malicious LNK file. Threat actors assigned this file a carefully crafted Pashto-language filename translating to “List of Employees Who Were Introduced to the Intellectual and Psychological Warfare Seminar.”

Using Pashto, the dominant language across Afghanistan’s government institutions, signals deep operational familiarity with the target environment and provincial finance officials.

Upon execution, the malware drops a decoy document containing a highly detailed provincial staff directory. This document spans all 34 provinces, listing Finance Directors, Revenue Chiefs, and direct mobile numbers in both Dari and Pashto.

Seqrite notes that this level of detail suggests extensive prior intelligence gathering by the threat actor before launching the campaign.

The campaign executes through a sophisticated infection chain engineered to minimize disk artifacts and evade detection at every layer.

Key stages in this deployment sequence include:

The final stage delivers XenoRAT 1.8.7, which connects to a command-and-control (C2) server over TCP using AES-encrypted, RTL-compressed traffic.

SideCopy enforces single-instance execution on the compromised host using the hardcoded mutex “clouda.” Once deployed, XenoRAT delivers a comprehensive post-exploitation toolkit featuring keylogging, screen capture, webcam surveillance, and SOCKS5 network tunneling.

Seqrite confirmed that this adoption of XenoRAT aligns with SideCopy’s documented shift toward customized open-source malware following prior AsyncRAT campaigns.

The attackers deliberately staged malicious traffic alongside legitimate Afghan government assets, routing the delivery domain to AS58469.

Furthermore, the RAT C2 server (185.235.137.106) relies on a Frankfurt-based bulletproof provider that has previously been tied to other SideCopy infrastructure clusters.

Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM .

Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

A critical authentication-bypass vulnerability affecting Palo Alto Networks PAN-OS and Prisma Access is being actively…

Google has officially made Device Bound Session Credentials (DBSC) generally available for the Chrome browser…

A newly analyzed ransomware strain, “The Gentlemen,” is raising concern among security researchers due to…

A newly identified threat actor tracked as JINX-0164 is targeting cryptocurrency organizations through sophisticated -based…

Threat actors are increasingly turning to generative AI tools such as ChatGPT and Google Gemini…

A newly discovered malicious NuGet package disguised as a legitimate Sicoob software development kit (SDK)…