Phishing, Government security, Email security

Afghan government offices subjected to phishing campaign

Afghan ministry and administrative office workers have been targeted with malware-spreading phishing emails purporting to be from the office of the country's prime minister as part of the Nomad Leopard campaign, according to The Record, a news site by cybersecurity firm Recorded Future.

Illicit emails with a decoy document appearing to be financial reporting instructions enabled the distribution of the FalseCub information-stealing malware from GitHub, a report from Seqrite showed. Additional analysis of the GitHub account used by the attacker led researchers to discover multiple administrative and legal files uploaded by the hacker under the "Afghan Khan" moniker across various platforms, including Dailymotion and Pinterest. Such a campaign may be launched by the "regionally focused threat actor" to target other countries.

"The threat actor is not very sophisticated but possesses multiple legal and government-related lure documents, which we believe may be used in future campaigns," said Seqrite researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds