Skip to content

SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry

Gbhackers Eswar May 30, 2026

Pakistan-linked threat actor SideCopy has launched a highly targeted spear-phishing campaign against Afghanistan’s Ministry of Finance (MoF). The operation surgically targets all 34 provincial revenue directorates, operating under the broader Transparent Tribe (APT36) umbrella. According to threat intelligence reports from Seqrite, the campaign culminates in the deployment of a customized XenoRAT 1.8.7 implant that beacons […]

Extracted Entities

APT Groups (2)

Attack Types (1)

Countries (2)

Malware (1)

MITRE ATT&CK (1)