Illustration showing a SideCopy spear-phishing campaign targeting Afghanistan's Ministry of Finance with Xeno RAT through a malicious LNK file and HTA-based malware delivery chain.

Pakistan-Linked SideCopy Targets Afghanistan’s Finance Ministry with Xeno RAT

Cybersecurity researchers have uncovered a new spear-phishing campaign believed to be carried out by the Pakistan-linked SideCopy threat group, targeting Afghanistan’s Ministry of Finance with the open-source Xeno RAT remote access trojan.

According to a technical analysis published by Seqrite Labs, the attack begins with a spear-phishing email delivering a ZIP archive that contains a malicious Windows shortcut (.LNK) file. The shortcut is disguised with a carefully crafted filename written in Pashto, the primary language used within Afghanistan’s government institutions.

Researchers found that the operation extends beyond the Ministry of Finance, targeting provincial finance and revenue departments, Pashto-speaking government officials, and employees working across regional government offices. Seqrite Labs has named the campaign Operation XENOFISCAL.

Using a Pashto-language lure demonstrates a deliberate effort by the attackers to increase the credibility of the phishing email. The language choice also indicates a strong understanding of the target environment and the individuals being targeted.

SideCopy is a Pakistan-linked cyber espionage group that operates under the broader Transparent Tribe (APT36) umbrella. The group has a long history of using multiple malware families to steal sensitive information from compromised systems. In April 2025, researchers linked SideCopy to attacks against organizations in India that deployed Xeno RAT, Spark RAT, and CurlBack RAT.

This is not the first campaign attributed to the threat group. Earlier, SideCopy was also linked to a phishing campaign targeting India’s Defence Research and Development Organisation (DRDO), where attackers deployed Action RAT against government systems. Read our detailed coverage of the SideCopy Action RAT campaign targeting India’s DRDO.

The newly identified campaign appears to be part of the group’s broader cyber operations focused on government and public-sector organizations across South Asia.

After the malicious LNK file is opened, it uses mshta.exe to retrieve a remote HTML Application (HTA) hosted on a compromised Afghan education-related domain. The HTA then executes heavily obfuscated JavaScript directly in memory, reducing the likelihood of detection.

To maintain long-term access, the malware creates Registry-based persistence while disguising itself as Microsoft Edge. Using a DLL-based loader, the attack deploys Xeno RAT 1.8.7 alongside a decoy document intended to distract the victim during the infection process.

Once installed, Xeno RAT communicates with its command-and-control (C2) server over TCP and supports a wide range of remote administration capabilities. These include loading external DLL modules, transferring files, executing attacker-issued commands, creating scheduled tasks for persistence, collecting antivirus information, enabling SOCKS5 proxy tunneling, performing file management operations, recording keystrokes, capturing screenshots, monitoring clipboard activity, accessing webcam and microphone devices, removing persistence mechanisms, and uninstalling itself when instructed.

The disclosure comes as researchers also revealed another targeted phishing campaign linked to Transparent Tribe that focuses on India’s military infrastructure. That operation uses weaponized Linux .desktop launcher files disguised as documents related to armored vehicle procurement contracts.

According to security researcher R.D. Tarun, the campaign relies on WhatsApp-based social engineering to lure targets into executing malicious files. Once launched, the Linux .desktop file triggers a heavily obfuscated shell-based infection chain that retrieves multiple payloads, performs inline decoding, and ultimately deploys a Golang-based ELF malware known as DeskRAT.

Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *