SUBJECT PROFILE
SideCopy, a Pakistan-linked sub-cluster of the broader Transparent Tribe (APT36) umbrella, disclosed a new campaign on June 2, 2026 (Operation XENOFISCAL) targeting Afghanistan's Ministry of Finance and all 34 provincial revenue and finance directorates. The group deployed Xeno RAT 1.8.7 via Pashto-language LNK lure files and a compromised Afghan education domain as a staging server, demonstrating operational familiarity with the Afghan government environment. The campaign is assessed as ongoing since at least May 2025 and reflects a sustained effort to collect national financial intelligence.
Espionage — financial intelligence collection targeting Afghan government fiscal infrastructure, consistent with Pakistan's regional geopolitical interests
OPERATIONAL HISTORY
Spear-phishing via ZIP/LNK files with Pashto-language filenames, mshta.exe abuse for remote HTA payload retrieval, in-memory JavaScript execution via obfuscated HTA, DLL-based loader chain dropping Xeno RAT 1.8.7, Registry-based persistence mimicking Microsoft Edge (HKCU Run key), compromised Afghan education domains as C2 staging infrastructure, decoy document lures (Afghan MoF staff directory), SOCKS5 proxying, keylogging, screenshot capture, LOTL via signed Windows binaries
KNOWN INFRASTRUCTURE
Xeno RAT 1.8.7 C2 hosted on bulletproof infrastructure (Bulgaria-based provider); initial staging via compromised Afghan education domain; LNK payload retrieved via mshta.exe; DLL loader drops final RAT payload with Registry-based Microsoft Edge process masquerade