Pakistan Spies on Afghan Finance Ministry With Xeno RAT

2026-06-04T08:51:44Ze9567c7c773c772a97613aea5ebb4118381c8ae066d967932f0c49f17bfdedae
AI-assisted exploit developmentAzureveilBTMOB RATClickFixDriveSurgeEDR evasionFakeUpdateGitHub supply-chainGlobalProtectGoogle GeminiKali365MegalodonPAN-OSSharePointTDSXeno RATcloud misconfigurationemail compromiseespionagenation-statephishing-as-a-serviceprompt-injectionransomware

What happened

This collection of DarkReading items highlights a surge in high-risk activity across multiple fronts: nation-state espionage (e.g., Pakistan targeting Afghanistan with Xeno RAT; China-linked campaigns in Latin America and against Czech/Taiwan organizations), active exploitation of product vulnerabilities (notably a PAN-OS/GlobalProtect authentication-bypass under active exploit and an out-of-band SharePoint patch), and widespread criminal operations (phishing-as-a-service Kali365, DriveSurge TDS delivering ClickFix/FakeUpdate, BTMOB RAT, Megalodon mass commits on GitHub). Attackers are also m—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
e9567c7c773c772a97613aea5ebb4118381c8ae066d967932f0c49f17bfdedae
Enrichment time
2026-06-04T08:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.