SideCopy Hits Afghan Finance Ministry With Xeno RAT in Pashto-Lure Phish
A new spear-phishing run tracked to the Pakistan-aligned cluster pairs LNK-laced ZIPs with an open-source RAT, in what looks like a continuation of the group's South and Central Asia espionage focus.

A spear-phishing operation aimed at Afghanistan's Ministry of Finance is being attributed, with medium confidence, to SideCopy — the Pakistan-aligned intrusion set that overlaps in tooling and infrastructure with Transparent Tribe (APT36).
The payload is Xeno RAT, an open-source remote access trojan that has steadily migrated from commodity crimeware kits into the toolboxes of state-aligned operators. SideCopy is not the first such cluster to adopt it. That reuse is precisely why analysts hedge on attribution when Xeno RAT shows up in isolation.
The lure is the interesting part.
Victims receive a ZIP archive containing a malicious Windows shortcut file with a Pashto-language filename, crafted to read as a legitimate ministry document. Pashto targeting, plus a finance ministry victim, plus SideCopy TTPs — the regional and sectoral fit is tight. LNK-based delivery has been a SideCopy staple for years, alongside HTA droppers and DLL sideloading chains.
Once executed, the LNK triggers a loader sequence that ultimately drops Xeno RAT, giving operators the usual menu: keystroke capture, file exfiltration, shell access, and remote control. Capability is broad. Intent, in this case, looks squarely collection-oriented rather than destructive.
Why this matters
SideCopy's interest in Afghan government entities is not new. The group expanded beyond Indian government and defense targeting around 2019 and has since hit Afghan diplomatic, military, and now finance-sector organizations. The Taliban-era ministry is a logical intelligence target for any neighboring service watching cross-border financial flows, sanctions exposure, or aid disbursements.
The shift to Xeno RAT is also worth flagging. SideCopy historically relied on custom implants such as ReverseRAT, ActionRAT, and AllaKore variants. Folding in an open-source RAT muddies attribution, lowers development cost, and gives the operators plausible deniability if samples surface in public repositories.
That said, the tradecraft around the RAT — the LNK staging, the Pashto social engineering, the victimology — is where the SideCopy fingerprint sits. The malware is interchangeable. The operation is not.
Detection notes
Defenders in the region should hunt for:
- LNK files executing
mshta.exe,powershell.exe, orcmd.exewith obfuscated arguments from user-writable paths - Outbound traffic to dynamic DNS providers historically abused by SideCopy infrastructure
- Xeno RAT mutex strings and configuration artifacts documented in open-source IOC feeds
- ZIP-delivered shortcuts with non-Latin-script filenames in mail gateways
Attribution caveat stands. Open-source RAT use means a copycat actor cannot be ruled out, but the lure language, targeting, and delivery pattern align with prior SideCopy activity at medium-to-high confidence.



