Executive Summary
In May 2026, the Pakistan-linked threat group SideCopy launched a spear-phishing campaign, dubbed Operation XENOFISCAL, targeting Afghanistan's Ministry of Finance and provincial finance officials. The attackers used ZIP archives containing malicious LNK files with Pashto-language filenames to deliver the open-source remote access trojan Xeno RAT. Once executed, the malware established persistence, enabling the attackers to exfiltrate sensitive data and maintain long-term access to compromised systems. This campaign underscores the persistent cyber threats facing governmental institutions in South Asia, highlighting the need for enhanced cybersecurity measures and vigilance against sophisticated phishing attacks.
Why This Matters Now
The Operation XENOFISCAL campaign highlights the ongoing cyber espionage activities targeting governmental institutions in South Asia. The use of localized language and tailored phishing tactics demonstrates the evolving sophistication of threat actors like SideCopy. Organizations must remain vigilant and implement robust security measures to defend against such targeted attacks.
Attack Path Analysis
The attack began with a spear-phishing email containing a ZIP archive with a malicious LNK file named in Pashto, targeting Afghan government officials. Upon execution, the LNK file used mshta.exe to fetch a remote HTA file from a compromised Afghan education domain, leading to the execution of obfuscated JavaScript in memory. This script established persistence by mimicking Microsoft Edge and deployed Xeno RAT via a DLL-based loader. Xeno RAT connected to a remote server over TCP, enabling the attacker to execute commands, perform file operations, and monitor the system. The malware facilitated data exfiltration through keylogging, screenshot capture, and clipboard monitoring. The ultimate impact was the unauthorized access and potential exfiltration of sensitive information from the Afghan Ministry of Finance.
Kill Chain Progression
Initial Compromise
Description
The attacker sent spear-phishing emails containing a ZIP archive with a malicious LNK file named in Pashto, targeting Afghan government officials.
MITRE ATT&CK® Techniques
Spearphishing Attachment
LNK Icon Smuggling
Malicious File
Ingress Tool Transfer
PowerShell
Web Protocols
DLL Side-Loading
Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Anti-Phishing Mechanisms
Control ID: 5.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Phishing-Resistant MFA
Control ID: Identity Pillar
NIS2 Directive – Incident Handling
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct target of Pakistan-linked SideCopy's Xeno RAT spear-phishing campaign against Afghanistan Finance Ministry, exposing critical government financial systems and sensitive data.
Financial Services
High risk from Remote Access Trojan targeting finance ministries; encrypted traffic and egress security controls essential to prevent data exfiltration and lateral movement.
Banking/Mortgage
Similar attack vectors threaten banking institutions through spear-phishing with malicious LNK files, requiring zero trust segmentation and threat detection capabilities.
Defense/Space
Nation-state SideCopy group's sophisticated campaign tactics pose significant threats to defense sectors requiring enhanced multicloud visibility and anomaly detection controls.
Sources
- Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAThttps://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.htmlVerified
- Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistanhttps://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/Verified
- About the Ministry | Ministry of Financehttps://www.mof.gov.af/en/about-ministryVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been limited to the compromised endpoint, reducing the likelihood of further exploitation.
Control: Zero Trust Segmentation
Mitigation: The execution of unauthorized scripts could have been constrained, reducing the attacker's ability to escalate privileges.
Control: East-West Traffic Security
Mitigation: The malware's ability to communicate with other internal systems may have been restricted, reducing lateral movement.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels could have been detected and disrupted, limiting the attacker's remote control capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: The exfiltration of sensitive data may have been prevented, reducing the risk of data loss.
The overall impact of the attack could have been minimized, reducing the exposure of sensitive information.
Impact at a Glance
Affected Business Functions
- Budget Management
- Tax Collection
- Public Expenditure Control
- Customs Management
Estimated downtime: 7 days
Estimated loss: N/A
Potential exposure of sensitive financial data, including budgetary information, tax records, and customs data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced email filtering to detect and block spear-phishing attempts.
- • Enforce strict execution policies to prevent unauthorized use of scripting interpreters like mshta.exe.
- • Deploy endpoint detection and response solutions to identify and mitigate malicious persistence mechanisms.
- • Monitor network traffic for unusual outbound connections to detect potential command and control communications.
- • Conduct regular security awareness training for employees to recognize and report phishing attempts.



