Seqrite Uncovers Operation XENOFISCAL: Pakistan-Linked SideCopy Group Deploys Persistent XenoRAT Against Afghanistan’s Ministry of Finance
A new chapter in South Asia’s cyber espionage story is unfolding far from the front page, inside finance ministries and provincial revenue offices. Seqrite, the enterprise security arm of Quick Heal Technologies Limited, a global provider of cybersecurity solutions, has disclosed details of Operation XENOFISCAL – a targeted cyber espionage campaign attributed with medium-to-high confidence to SideCopy, a Pakistan-linked advanced persistent threat (APT) group operating under the broader Transparent Tribe/APT36 umbrella.
Researchers at Seqrite Labs, India’s largest malware analysis facility, discovered that the operation implants a persistent variant of XenoRAT 1.8.7 across Afghanistan’s Ministry of Finance (MoF) and provincial revenue directorates, using carefully crafted Pashto-language spear-phishing lures and a multi-stage, largely fileless infection chain that abuses legitimate Windows binaries to bypass traditional defenses.
The campaign begins with a spear-phishing email carrying a ZIP archive that appears, at first glance, to be a routine internal document. Inside sits a...
Copyright of this story solely belongs to itvoice.in. To see the full text click HERE