Acronis Threat Research Unit (TRU) has identified a new ongoing campaign deploying a previously undocumented backdoor called PATCHCORD. This campaign specifically targets Afghan telecom providers and critical infrastructure organizations across South Asia. The malware is delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
The activity is assessed with moderate confidence to be the work of APT36, also known as Transparent Tribe, a Pakistan-aligned threat actor. This attribution is based on overlaps in targeting patterns, similarities in malware, shared infrastructure, and operational tradecraft observed by researchers.
The initial infection vector is typically a ZIP archive, "Telecom_TMS.zip," containing an Inno Setup installer, "TMS_AfghanTelecom.exe." This installer delivers PATCHCORD. TMS refers to Transport Management System, an internal system used by Afghan Telecom. Upon execution, PATCHCORD establishes persistence by hijacking browser shortcuts for Chrome, Edge, and Firefox, fingerprints the host, and registers with its command-and-control (C2) server.
PATCHCORD's capabilities include adjusting C2 beacon intervals, enumerating running processes, decoding and executing shellcode payloads from the C2 server, and executing arbitrary commands via "cmd.exe." It also provides interactive control over the browser shortcut hijacking mechanism, allowing it to launch legitimate browsers while operating in the background.
Analysis of the threat actor's infrastructure also revealed another Go-based backdoor named SHEETCORD. This malware utilizes Google Sheets for its command-and-control communications. SHEETCORD has been observed being delivered via a domain impersonating India's National Informatics Center (NIC). The campaign's infrastructure relies on a single C2 server with multiple associated domains, including those impersonating Afghan telecom operators and a hijacked legitimate healthcare domain.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new backdoor named PATCHCORD is targeting Afghan telecom providers and South Asian critical infrastructure organizations. This campaign, attributed to the Pakistan-aligned APT36, uses sector-specific lures like fake VPN installers and impersonated government domains to deliver malware capable of remote command execution and data exfiltration.