惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
Jina AI
Jina AI
月光博客
月光博客
博客园 - Franky
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
有赞技术团队
有赞技术团队
V
V2EX
IT之家
IT之家
阮一峰的网络日志
阮一峰的网络日志
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
腾讯CDC
D
DataBreaches.Net
Hugging Face - Blog
Hugging Face - Blog
Martin Fowler
Martin Fowler
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
WordPress大学
WordPress大学
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
Microsoft Security Blog
Microsoft Security Blog

The Record from Recorded Future News

Taiwan charges two businessmen over alleged role in Chinese espionage campaign Former UK privacy chief preparing legal action against woman who reported him, minister says Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip EU unveils cyber plan to reduce reliance on foreign AI systems Supreme Court allows Texas app law requiring age verification to take effect Britain plans to build autonomous AI 'Cyber Shield' to defend nation Major Japanese telco says cyberattack exposed 12 million emails UK cyber pledge draws only a handful of top firms despite ministerial appeal Canadian spy agency reports hacking three criminal groups in 2025 Attackers vote themselves $20 million in BONK cryptocurrency Major medical device manufacturer notifies nearly 4 million of breach Japanese teen arrested over cyberattack that disrupted anime streaming service Ukrainian media outlets now among 'priority targets' for Russian hackers Spyware found on phone of European Parliament member probing it Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis Supreme Court decision threatens EU-US data transfer agreement Teen suspect in Scattered Spider hacks is extradited to US US lifts export controls on Anthropic’s frontier cybersecurity AI models Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches CIA chief highlights major shifts in agency’s tech approach House passes kids’ online safety bill, but Senate approval unlikely An intelligence budget 'super user' job is now in the hands of Russ Vought Justices rule that cellphone location histories are protected by the Fourth Amendment US racks up about 400 wins over illegal World Cup streaming sites US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp Ukraine to use seized crypto from cybercrime group to buy war bonds Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Turla group adds more malware to Russia’s espionage efforts against Ukraine Russia used social engineering to breach prominent messaging accounts, Ukraine says FCC votes to toughen rules in bid to better protect undersea cables
Afghan finance officials targeted by suspected Pakistani ...
Daryna Antoniuk · 2026-06-01 · via The Record from Recorded Future News

A suspected Pakistan-linked hacking group has targeted Afghanistan's Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found.

Indian cybersecurity firm Seqrite attributed the operation with medium-to-high confidence to SideCopy, a threat actor widelyl linked to Pakistan and known for targeting government, military and diplomatic entities across South Asia.

The attackers used phishing emails containing ZIP archives with a malicious file masquerading as an internal government document. The file's title, written in Pashto, claimed to contain a list of employees who had participated in a seminar on intellectual and psychological warfare.

The malicious files were delivered through infrastructure hosted on Afghan government servers, allowing the attackers to blend their traffic with legitimate state communications and evade network-level detection. It is not known how SideCopy gained access to the compromised Afghan education domain server.

Once opened, the file silently installed XenoRAT, an open-source remote access trojan that allows attackers to maintain long-term access to infected systems. The malware then connected to attacker-controlled servers hosted in Europe, allowing the attackers to spy on infected computers and carry out additional malicious activities.

According to Seqrite, the use of Pashto was likely intentional. The language is widely used across Afghanistan's government institutions and among the provincial finance officials who appeared to be the primary targets of the operation.

Researchers said the lure document demonstrated a level of specificity that suggests the attackers conducted reconnaissance before launching the campaign.

"While the victim reads what appears to be a routine internal government document, the malware has already silently completed its installation in the background," Seqrite researchers wrote.

The operation targeted not only Afghanistan's Ministry of Finance but also provincial revenue and finance directorates, Pashto-speaking government officials and other provincial government employees, according to the report.

SideCopy has been active since at least 2019 and has frequently been linked by researchers to operations resembling those of APT36, also known as Transparent Tribe, a hacking group associated with Pakistan. Seqrite previously observed SideCopy deploying customized versions of XenoRAT in late 2024 as part of a broader overhaul of its malware toolkit.

This is not the first time Afghan officials have been targeted in a phishing campaign. In a separate operation reported by Seqrite in January, unknown hackers targeted Afghan government employees with phishing emails disguised as official correspondence from the Prime Minister's office. Those emails delivered a data-stealing malware strain known as FalseCub. Researchers did not publicly attribute that operation to a specific threat actor.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.