Nomad Leopard is a regionally focused cyber-espionage threat actor tracked for phishing campaigns against Afghan government personnel. The group has used lures crafted to resemble official correspondence from Afghanistan’s prime minister’s office and other ministry or administrative notices, indicating prior research into Afghan government institutions and Taliban-linked entities. Reported lure themes include legal, administrative, defense, asylum, and human-rights documents related to Afghanistan, suggesting an expanding library of pretexts for future operations. Observed intrusion activity relied on phishing emails delivering attachments presented as legitimate government documents. In documented cases, the infection chain used an ISO archive containing a malicious Windows shortcut that launched a concealed executable disguised to appear benign. The delivered malware, identified as FalseCub, was used to collect and exfiltrate data from compromised systems. The actor also used public developer and content-sharing platforms to stage or distribute payloads and lure material, a tactic consistent with blending malicious traffic into legitimate services. Nomad Leopard has been associated with the reused online persona "Afghan Khan," which appeared across multiple platforms. This repeated persona reuse has been assessed as poor operational security and supports the view that the activity is more consistent with an individual operator or small cluster than with a mature state-sponsored advanced persistent threat organization. The actor has been assessed as low-to-moderate in sophistication. Although some traces were linked to Pakistan, attribution to a specific country or known threat group remains unconfirmed. The dominant observed objective is espionage against Afghan government targets, and the campaign may expand beyond Afghanistan.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Regionally focused phishing campaign targeting Afghan government employees using decoy government letters to deliver the FalseCub infostealer; uses GitHub for temporary payload hosting and leverages legal/government documents (e.g., Afghan directives, Ministry of Defense communications, U.S. asylum/human-rights documents) as lure material.
Cyber-espionage campaign targeting Afghan government ministries and administrative offices via phishing emails with official-looking lure documents. Delivery uses ISO attachments containing malicious LNK shortcuts that execute a hidden payload (an executable renamed to resemble an image). The actor abuses GitHub repositories to host/distribute payloads and blend into legitimate traffic; OPSEC mistakes (persona reuse across platforms) suggest a small cluster/individual with low-to-moderate sophistication.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.