PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure

PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure

First seen 13 Aug 2026, 16:49 UTC Acronisnvd.nist.govsecurelist.comxelemental.github.io 97% similarity 73.5

Article Content

Browse articles
ThreatCluster

Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is delivered through fake VPN installers impersonating Afghan Telecom. The campaign also includes a Go-based implant, SHEETCORD, which utilizes Google Sheets for command and control communication. The malware was distributed via a domain mimicking India's National Informatics Centre. The campaign's infrastructure relies on a single command and control server with multiple domains, including hijacked healthcare domains. The investigation revealed a toolkit comprising various remote access tools, credential harvesting tools, and exploit tooling for CVE-2024-6387. TRU assesses with moderate confidence that this campaign is linked to the APT36 (Transparent Tribe) group, indicating an evolution in their targeting and operational tactics. The campaign reflects a shift towards Afghan telecom providers and critical sectors like government and energy. The investigation began after discovering a malicious ZIP archive on VirusTotal in June 2026.

Key Points: • PATCHCORD is a new malware targeting Afghan telecom and South Asian infrastructure. • The malware is delivered via fake VPN installers and includes a Go-based implant for C2. • The campaign is linked to the APT36 group, indicating a shift in their operational focus.

ThreatCluster AI How this analysis works

Timeline

2022-01-28
CVE-2021-4034 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-07-01
CVE-2024-6387 published
CVE-2024-6387, an exploit used in the PATCHCORD campaign, was published, indicating a vulnerability in systems.
Acronis
2026-06-01
Malicious ZIP archive discovered
A suspicious ZIP archive named Telecom_TMS was found on VirusTotal, leading to the investigation of PATCHCORD.
Acronis
2026-08-13
PATCHCORD campaign reported
Acronis TRU published findings on the PATCHCORD malware campaign targeting Afghan telecom and critical infrastructure.
Acronis

Community

Browse all →