Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
seqrite.2026.operation-xenofiscal-sidecopy-xenorat
Operation XENOFISCAL: Pashto LNK to compromised Afghan delivery host and XenoRAT C2
|
SideCopy | confirmed | 2 spearphishing ZIP archive targeting... | — | 13 mshta.exe LOLBIN execution of remot... | 3 ayhui.vmxx reconstructed shellcode ... | 1 185.235.137.106 | 19e / 18r | 2026-05-29 20:01:27 |
Technique pressure
top observed IIM techniquesActor surface
published chain attributionseqrite.2026.operation-xenofiscal-sidecopy-xenorat
Operation XENOFISCAL: Pashto LNK to compromised Afghan delivery host and XenoRAT C2
IIM chain for Seqrite Operation XENOFISCAL, published 2026-05-29. The campaign targets Afghanistan Ministry of Finance provincial officials with a spearphishing ZIP containing a Pashto malicious LNK. The LNK launches mshta.exe and retrieves obfuscated HTA/JavaScript from compromised Afghan education domain abimj.edu.af/index.php. The script reconstructs an in-memory .NET loader, downloads an Afghan Ministry of Finance decoy PDF, persists zuidrt.hta, retrieves additional payload blobs from /institute/10/ or /institute/7/, reconstructs shellcode, loads XenoRAT, and connects to hardcoded C2 IP 185.235.137.106 hosted on AS59711/HZ Hosting infrastructure.