Acronis PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Article Content
- •PATCHCORD is a new malware targeting Afghan telecom and South Asian infrastructure.
- •The malware is delivered via fake VPN installers and includes a Go-based implant for C2.
- •The campaign is linked to the APT36 group, indicating a shift in their operational focus.
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is delivered through fake VPN installers impersonating Afghan Telecom. The campaign also includes a Go-based implant, SHEETCORD, which utilizes Google Sheets for command and control communication. The malware was distributed via a domain mimicking India's National Informatics Centre. The campaign's infrastructure relies on a single command and control server with multiple domains, including hijacked healthcare domains. The investigation revealed a toolkit comprising various remote access tools, credential harvesting tools, and exploit tooling for CVE-2024-6387. TRU assesses with moderate confidence that this campaign is linked to the APT36 (Transparent Tribe) group, indicating an evolution in their targeting and operational tactics. The campaign reflects a shift towards Afghan telecom providers and critical sectors like government and energy. The investigation began after discovering a malicious ZIP archive on VirusTotal in June 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Apt36, ABCDoor and Afghan Telecom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
APT36 Launches Operation RapidRust with New Rust Malware Tools In August 2026, the Pakistan-nexus threat actor APT36 initiated Operation RapidRust, targeting government and defense organizations in India and Afghanistan. The campaign introduced several new Rust-based malware tools, including the RUSTYSHADE backdoor and RUSTYMOVE propagation tool. APT36 also deployed file-stealing…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…