Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
Researchers say SideCopy used a Pashto-lure ZIP and LNK file to target Afghanistan’s finance ministry, delivering Xeno RAT through a staged infection chain.
Intelligence analysis by GPT-5.4 Mini

Seqrite Labs says the Pakistan-aligned SideCopy group ran Operation XENOFISCAL against Afghan finance and revenue offices using a Pashto-themed spear-phishing lure. The infection chain used LNK, HTA, and JavaScript steps to drop Xeno RAT and keep persistence.
Hackers used a fake file that looked familiar to Afghan officials, like a bait package with a hidden trap inside. When someone clicked it, it quietly opened a back door so the attackers could spy and poke around the computer.
Analysis
What happened
Seqrite Labs says a Pakistan-aligned group tracked as SideCopy targeted Afghanistan’s Ministry of Finance and related provincial finance and revenue offices in a campaign it calls Operation XENOFISCAL. The lure was a ZIP archive containing a malicious LNK file with a Pashto-language filename, which appears designed for the Afghan government environment.
How the attack worked
According to the report, the shortcut file uses mshta.exe to pull down a remote HTA file from a compromised Afghan education domain. That leads to obfuscated JavaScript running in memory, followed by registry-based persistence designed to imitate Microsoft Edge. The chain then drops Xeno RAT 1.8.7 and a decoy document, using a DLL-based loader to distract the victim.
Why the payload matters
Xeno RAT is described as a remote access trojan that connects to an operator over TCP and can load DLL modules, move files, log keystrokes, take screenshots, monitor the clipboard, and interact with webcam and microphone devices. The report also says it supports SOCKS5 proxy tunneling, scheduled-task launch, antivirus checks, persistence removal, and self-uninstall.
Broader context
The article frames SideCopy as part of the broader Transparent Tribe, also known as APT36, which has used multiple malware families against South Asian targets before. It also notes a separate phishing campaign against Indian military infrastructure using weaponized Linux .desktop files and a Golang implant called DeskRAT. Taken together, the piece suggests a continuing pattern of tailored social engineering, staged payload delivery, and reuse of modular malware across regional targets.
Key points
- Seqrite Labs attributes the campaign to SideCopy, a Pakistan-linked group under the Transparent Tribe umbrella.
- The lure used a Pashto-named ZIP file containing a malicious Windows LNK shortcut.
- The infection chain used mshta.exe, a remote HTA file, and obfuscated JavaScript to deliver Xeno RAT.
- The malware can log keystrokes, capture screenshots, monitor the clipboard, and support SOCKS5 tunneling.
- The article also notes a separate Transparent Tribe campaign against Indian military infrastructure using DeskRAT.
The disclosure gives defenders a clear picture of the lure format, execution chain, and malware behaviors to watch for. Security teams in government networks can use those details to block similar ZIP, LNK, and HTA-based attacks earlier.
If the campaign succeeds, attackers can keep access, steal files, watch screens, log keystrokes, and move data through proxy channels. The reuse of related tactics across South Asian targets suggests the same playbook could keep showing up in other government environments.



