DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // SIDECOPY-OPERATION-XENOFISCALFIRST SEEN: MAY 2025

SideCopy (APT36 / Transparent Tribe)

ALSO KNOWN AS: Transparent Tribe, APT36, Operation XENOFISCAL (campaign name)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Pakistan (attributed with high confidence by Seqrite Labs, June 2026)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:MAY 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL61/100
RESOURCES69/100
PERSISTENCE69/100
STEALTH69/100
IMPACT61/100

SideCopy, a Pakistan-linked sub-cluster of the broader Transparent Tribe (APT36) umbrella, disclosed a new campaign on June 2, 2026 (Operation XENOFISCAL) targeting Afghanistan's Ministry of Finance and all 34 provincial revenue and finance directorates. The group deployed Xeno RAT 1.8.7 via Pashto-language LNK lure files and a compromised Afghan education domain as a staging server, demonstrating operational familiarity with the Afghan government environment. The campaign is assessed as ongoing since at least May 2025 and reflects a sustained effort to collect national financial intelligence.

Espionage — financial intelligence collection targeting Afghan government fiscal infrastructure, consistent with Pakistan's regional geopolitical interests

Spear-phishing via ZIP/LNK files with Pashto-language filenames, mshta.exe abuse for remote HTA payload retrieval, in-memory JavaScript execution via obfuscated HTA, DLL-based loader chain dropping Xeno RAT 1.8.7, Registry-based persistence mimicking Microsoft Edge (HKCU Run key), compromised Afghan education domains as C2 staging infrastructure, decoy document lures (Afghan MoF staff directory), SOCKS5 proxying, keylogging, screenshot capture, LOTL via signed Windows binaries

GOVERNMENT
FINANCE
PUBLIC SECTOR
DEFENSE

Xeno RAT 1.8.7 C2 hosted on bulletproof infrastructure (Bulgaria-based provider); initial staging via compromised Afghan education domain; LNK payload retrieved via mshta.exe; DLL loader drops final RAT payload with Registry-based Microsoft Edge process masquerade

FILE DATE: MAY 2025
Operation XENOFISCAL
Sustained spear-phishing campaign targeting Afghanistan's Ministry of Finance and all 34 provincial revenue directorates using Pashto-language lures and Xeno RAT to exfiltrate financial governance intelligence.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn