APT36 Exploits Google Sheets for PATCHCORD Espionage Against Afghan Telecom

APT36 Exploits Google Sheets for PATCHCORD Espionage Against Afghan Telecom

First seen 16 Aug 2026, 09:17 UTC ThehackernewsSecurityaffairs.Co 72% similarity 72.5

Article Content

Browse articles
ThreatCluster

Acronis has identified a new backdoor named PATCHCORD, attributed to APT36, targeting Afghan telecom and South Asian infrastructure. The attack utilizes fake VPN tools and Google Sheets as command and control (C2) infrastructure. This espionage campaign is particularly stealthy, indicating a sophisticated approach to disguise malicious activities. The backdoor is designed to infiltrate critical systems, posing a significant risk to the affected sectors. The operation appears to be ongoing, with Acronis documenting its findings in a recent report. The specific tools and methods used in this campaign have not been disclosed in detail, but the implications for national security are considerable. Organizations in the targeted regions are advised to enhance their security measures against such threats.

Key Points: • APT36 is using a new backdoor called PATCHCORD for espionage activities. • The attack targets Afghan telecom and South Asian infrastructure through fake VPNs. • Google Sheets is utilized as a command and control mechanism for the malware.

ThreatCluster AI How this analysis works

Timeline

2026-08-13
PATCHCORD backdoor identified
Acronis reported the discovery of PATCHCORD, a backdoor targeting Afghan telecom and Indian infrastructure.
Thehackernews
2026-08-16
Acronis publishes detailed report
Acronis released a report detailing the stealthy nature of the PATCHCORD backdoor and its operational methods.
Securityaffairs.Co

Community

Browse all →