惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
The GitHub Blog
The GitHub Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
小众软件
小众软件
博客园_首页
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
D
Docker
B
Blog
雷峰网
雷峰网
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享

The Record from Recorded Future News

Taiwan charges two businessmen over alleged role in Chinese espionage campaign Former UK privacy chief preparing legal action against woman who reported him, minister says Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip EU unveils cyber plan to reduce reliance on foreign AI systems Supreme Court allows Texas app law requiring age verification to take effect Britain plans to build autonomous AI 'Cyber Shield' to defend nation Major Japanese telco says cyberattack exposed 12 million emails UK cyber pledge draws only a handful of top firms despite ministerial appeal Canadian spy agency reports hacking three criminal groups in 2025 Attackers vote themselves $20 million in BONK cryptocurrency Major medical device manufacturer notifies nearly 4 million of breach Japanese teen arrested over cyberattack that disrupted anime streaming service Ukrainian media outlets now among 'priority targets' for Russian hackers Spyware found on phone of European Parliament member probing it Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis Supreme Court decision threatens EU-US data transfer agreement Teen suspect in Scattered Spider hacks is extradited to US US lifts export controls on Anthropic’s frontier cybersecurity AI models Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches CIA chief highlights major shifts in agency’s tech approach House passes kids’ online safety bill, but Senate approval unlikely An intelligence budget 'super user' job is now in the hands of Russ Vought Justices rule that cellphone location histories are protected by the Fourth Amendment US racks up about 400 wins over illegal World Cup streaming sites US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp Ukraine to use seized crypto from cybercrime group to buy war bonds Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Turla group adds more malware to Russia’s espionage efforts against Ukraine Russia used social engineering to breach prominent messaging accounts, Ukraine says FCC votes to toughen rules in bid to better protect undersea cables
Afghan finance officials targeted by suspected Pakistani ...
Daryna Antoniuk · 2026-06-01 · via The Record from Recorded Future News

A suspected Pakistan-linked hacking group has targeted Afghanistan's Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found.

Indian cybersecurity firm Seqrite attributed the operation with medium-to-high confidence to SideCopy, a threat actor widelyl linked to Pakistan and known for targeting government, military and diplomatic entities across South Asia.

The attackers used phishing emails containing ZIP archives with a malicious file masquerading as an internal government document. The file's title, written in Pashto, claimed to contain a list of employees who had participated in a seminar on intellectual and psychological warfare.

The malicious files were delivered through infrastructure hosted on Afghan government servers, allowing the attackers to blend their traffic with legitimate state communications and evade network-level detection. It is not known how SideCopy gained access to the compromised Afghan education domain server.

Once opened, the file silently installed XenoRAT, an open-source remote access trojan that allows attackers to maintain long-term access to infected systems. The malware then connected to attacker-controlled servers hosted in Europe, allowing the attackers to spy on infected computers and carry out additional malicious activities.

According to Seqrite, the use of Pashto was likely intentional. The language is widely used across Afghanistan's government institutions and among the provincial finance officials who appeared to be the primary targets of the operation.

Researchers said the lure document demonstrated a level of specificity that suggests the attackers conducted reconnaissance before launching the campaign.

"While the victim reads what appears to be a routine internal government document, the malware has already silently completed its installation in the background," Seqrite researchers wrote.

The operation targeted not only Afghanistan's Ministry of Finance but also provincial revenue and finance directorates, Pashto-speaking government officials and other provincial government employees, according to the report.

SideCopy has been active since at least 2019 and has frequently been linked by researchers to operations resembling those of APT36, also known as Transparent Tribe, a hacking group associated with Pakistan. Seqrite previously observed SideCopy deploying customized versions of XenoRAT in late 2024 as part of a broader overhaul of its malware toolkit.

This is not the first time Afghan officials have been targeted in a phishing campaign. In a separate operation reported by Seqrite in January, unknown hackers targeted Afghan government employees with phishing emails disguised as official correspondence from the Prime Minister's office. Those emails delivered a data-stealing malware strain known as FalseCub. Researchers did not publicly attribute that operation to a specific threat actor.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.