Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Ministry of Foreign Affairs of the Islamic Republic of Afghanistan

Ministry of Foreign Affairs of the Islamic Republic of Afghanistan Vendor Cyber Rating & Cyber Score

mfa.gov.af


MFAIRA A.I CyberSecurity Scoring

MFAIRA
Company Information
Website:https://www.mfa.gov.af/
Employees number:157
Number of followers:842
NAICS:541821
Industry Type:Government Relations Services
Homepage:mfa.gov.af
MFAIRA Risk Score (AI oriented)
Between 700 and 749
logo
MFAIRAGovernment Relations Services
Updated:
15/07/2026
736/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MFAIRA Global Score (TPRM)
xxxx
logo
MFAIRAGovernment Relations Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MFAIRA
MFAIRAModerate
Current Score
736Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
737Before Incident
AUGUST 2026
737Before Incident
JULY 2026
736Before Incident
JUNE 2026
753Before Incident
Cyber Attack
01 Jun 2026MFAIRA
Government of Taiwan, Government of Thailand and Government of Afghanistan: Suspected Chinese Hackers Use Claude Code and DeepSeek to Breach Government Systems in Three Countries

AI-Powered Cyber Espionage Campaign Targets Government Entities in Asia

736After Incident
CRITICAL-17
MOFOFFTAI1784103925
AI-Powered Cyber Espionage Campaign Targets Government Entities in Asia In June 2026, security researchers uncovered an active cyber espionage campaign leveraging AI models Claude Code and DeepSeek-v4-pro to compromise government organizations in Afghanistan, Thailand, and Taiwan. The operation, linked to suspected China-aligned threat actors, was identified after analysts traced infrastructure associated with TencShell, a Go-based implant previously flagged by Cato CTRL for similar activity. The investigation began with an exposed server (112.213.124[.]132), which contained a trove of malicious assets, including victim source code, exploit tools, phishing templates, operator logs, and malware samples all documented in Simplified Chinese. The threat actors employed a split-model workflow: DeepSeek-v4-pro handled attack reasoning, exploit adaptation, and script generation, while Claude Code managed command execution, persistent sessions, and phishing page development. This marks the second documented case of suspected China-linked operators using Claude Code in cyber operations, following a November 2025 disclosure by Anthropic. The campaign’s infrastructure, primarily hosted in Hong Kong by providers like VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited, included 13 servers sharing a unique HTTP header fingerprint. The exposed server hosted multiple services, such as: - SSH (port 222222) - Malware download service (port 111111111111) - DeepAudit (port 300030003000) – a legitimate open-source tool repurposed for reconnaissance - ARL (port 500350035003) – another open-source tool used for malicious scanning - Vshell (port 808480848084) – command-and-control software - Open HTTP directory (port 888888888888) – containing 2,431 files and 80 subdirectories, including web shells, database dumps, exploit scripts, and cloned government login pages The directory also revealed Linux malware compiled for ARM systems, designed to steal cloud access keys, enterprise credentials, and Tencent QQ/IM data, while enabling file exfiltration. Researchers identified shared SSH host keys and default ARL TLS certificates across three servers, indicating coordinated infrastructure. Additionally, a potential second C2 framework, "Gshell," was detected, with overlapping servers suggesting the operators use multiple frameworks in tandem. The campaign underscores the growing use of AI-driven tools in state-sponsored cyber operations, blending legitimate software with custom malware to evade detection and enhance attack efficiency.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Cyber Espionage
IMPACT
Cloud access keysEnterprise credentialsTencent QQ/IM dataVictim source codeDatabase dumpsGovernment systemsARM-based Linux systems
DATA BREACH
Cloud access keysEnterprise credentialsTencent QQ/IM dataSource codeDatabase dumpsSensitivity Of Data: HighWeb shellsExploit scriptsCloned government login pages
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MFAIRA ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in August 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in July 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in June 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MFAIRA's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on MFAIRA's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MFAIRA ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MFAIRA's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Ministry of Foreign Affairs of the Islamic Republic of Afghanistan Cyber Scoring History | Rankiteo