Securityaffairs.Co
APT36 Exploits Google Sheets for PATCHCORD Espionage Against Afghan Telecom
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Acronis has identified a new backdoor named PATCHCORD, attributed to APT36, targeting Afghan telecom and South Asian infrastructure. The attack utilizes fake VPN tools and Google Sheets as command and control (C2) infrastructure. This espionage campaign is particularly stealthy, indicating a sophisticated approach to disguise malicious activities. The backdoor is designed to infiltrate critical systems, posing a significant risk to the affected sectors. The operation appears to be ongoing, with Acronis documenting its findings in a recent report. The specific tools and methods used in this campaign have not been disclosed in detail, but the implications for national security are considerable. Organizations in the targeted regions are advised to enhance their security measures against such threats.
Key Points: • APT36 is using a new backdoor called PATCHCORD for espionage activities. • The attack targets Afghan telecom and South Asian infrastructure through fake VPNs. • Google Sheets is utilized as a command and control mechanism for the malware.