Researchers have uncovered a targeted cyber espionage campaign, dubbed Operation XENOFISCAL, attributed to the Pakistan-aligned threat group SideCopy. The operation primarily targets Afghanistan’s Ministry of Finance, provincial revenue offices, and government officials through carefully crafted spear-phishing attacks. By using Pashto-language lures tailored to Afghan government personnel, the attackers demonstrate detailed knowledge of the target environment and increase the likelihood of successful compromise. The attack begins with a phishing email containing a ZIP archive that includes a malicious Windows shortcut (LNK) file. When executed, the shortcut leverages mshta.exe to retrieve a remote HTML Application (HTA) hosted on a compromised Afghan domain. The HTA launches obfuscated JavaScript in memory, which subsequently deploys a DLL-based loader responsible for installing Xeno RAT while simultaneously displaying a decoy document to avoid suspicion. Once active, Xeno RAT establishes communication with a command-and-control server and provides extensive remote access capabilities. The malware can execute commands, transfer files, capture keystrokes, monitor clipboard activity, take screenshots, access webcams and microphones, and create persistence through Windows Registry modifications. Researchers assess the activity as part of SideCopy’s broader cyber espionage operations targeting government and strategic entities across South Asia.
A recently disclosed supply chain vulnerability in Anthropic’s Claude Code GitHub Actions integration exposed numerous repositories to potential compromise through a single malic...
A critical security vulnerability affecting KMW CCTV cameras has been disclosed under CVE-2026-5386. The flaw allows attackers to bypass authentication controls and change device c...
A critical vulnerability, tracked as CVE-2026-4387, has been disclosed in StrongDM, exposing organizations to authentication token theft and session hijacking. Discovered by Specte...