Pakistan Spies on Afghan Finance Ministry With Xeno RAT
A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The group utilized a Xeno RAT remote stealer, employing spear-phishing tactics and leveraging the country's existing digital infrastructure, including a compromised domain hosted in Afghanistan's Ministry of Communication and Information Technology, to gain access and exfiltrate data. This operation highlights the ongoing cybersecurity challenges faced by Afghanistan and the evolving tactics of threat actors operating within the region.
The attack began with spear-phishing emails containing malicious LNK files disguised as PDFs, which then executed an HTA payload to deploy the Xeno RAT. The RAT, an open-source remote stealer, was customized with a hardcoded command-and-control (C2) domain hosted on a bulletproof service in Bulgaria. The attackers established persistence through the Windows registry, mimicking a Microsoft Edge process. The initial target was an Afghan Ministry of Finance staff directory, listing names and mobile numbers of high-ranking employees across the country. This tactic, combined with the use of the Pashto language, demonstrated a deliberate effort to blend in with the local environment and increase the likelihood of success. The operation’s sophistication lies in its execution and orchestration of established TTPs rather than novel techniques.
This campaign is fueled by the legacy of foreign aid and investment in Afghanistan’s digital infrastructure following the 2001 invasion. The Taliban inherited a complex network of mobile, fiber optic, and IT services, including security and surveillance systems. However, the Taliban now faces significant cybersecurity challenges due to limited resources. The Pakistan-based SideCopy group exploited this situation, leveraging the existing infrastructure to conduct its espionage activities. The use of a compromised domain within the Ministry of Communication and Information Technology’s IP address space further enhanced the group’s ability to evade detection.
