Pakistan Spies on Afghan Finance Ministry With Xeno RAT
2026-06-04T08:51:44Z•e9567c7c773c772a97613aea5ebb4118381c8ae066d967932f0c49f17bfdedae
AI-assisted exploit developmentAzureveilBTMOB RATClickFixDriveSurgeEDR evasionFakeUpdateGitHub supply-chainGlobalProtectGoogle GeminiKali365MegalodonPAN-OSSharePointTDSXeno RATcloud misconfigurationemail compromiseespionagenation-statephishing-as-a-serviceprompt-injectionransomware
What happened
This collection of DarkReading items highlights a surge in high-risk activity across multiple fronts: nation-state espionage (e.g., Pakistan targeting Afghanistan with Xeno RAT; China-linked campaigns in Latin America and against Czech/Taiwan organizations), active exploitation of product vulnerabilities (notably a PAN-OS/GlobalProtect authentication-bypass under active exploit and an out-of-band SharePoint patch), and widespread criminal operations (phishing-as-a-service Kali365, DriveSurge TDS delivering ClickFix/FakeUpdate, BTMOB RAT, Megalodon mass commits on GitHub). Attackers are also m—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- e9567c7c773c772a97613aea5ebb4118381c8ae066d967932f0c49f17bfdedae
- Enrichment time
- 2026-06-04T08:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.