Skip to content
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure

PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure

First seen 13 Aug 2026, 16:49 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 14, 2026 at 16:29 UTC
  • •PATCHCORD is a new malware targeting Afghan telecom and South Asian infrastructure.
  • •The malware is delivered via fake VPN installers and includes a Go-based implant for C2.
  • •The campaign is linked to the APT36 group, indicating a shift in their operational focus.

Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is delivered through fake VPN installers impersonating Afghan Telecom. The campaign also includes a Go-based implant, SHEETCORD, which utilizes Google Sheets for command and control communication. The malware was distributed via a domain mimicking India's National Informatics Centre. The campaign's infrastructure relies on a single command and control server with multiple domains, including hijacked healthcare domains. The investigation revealed a toolkit comprising various remote access tools, credential harvesting tools, and exploit tooling for CVE-2024-6387. TRU assesses with moderate confidence that this campaign is linked to the APT36 (Transparent Tribe) group, indicating an evolution in their targeting and operational tactics. The campaign reflects a shift towards Afghan telecom providers and critical sectors like government and energy. The investigation began after discovering a malicious ZIP archive on VirusTotal in June 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2022-01-28
CVE-2021-4034 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-07-01
CVE-2024-6387 published
CVE-2024-6387, an exploit used in the PATCHCORD campaign, was published, indicating a vulnerability in systems.
Acronis
2026-06-01
Malicious ZIP archive discovered
A suspicious ZIP archive named Telecom_TMS was found on VirusTotal, leading to the investigation of PATCHCORD.
Acronis
2026-08-13
PATCHCORD campaign reported
Acronis TRU published findings on the PATCHCORD malware campaign targeting Afghan telecom and critical infrastructure.
Acronis

More articles in this cluster (10)

Following this threat?

Track Apt36, ABCDoor and Afghan Telecom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed