Acronis
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is delivered through fake VPN installers impersonating Afghan Telecom. The campaign also includes a Go-based implant, SHEETCORD, which utilizes Google Sheets for command and control communication. The malware was distributed via a domain mimicking India's National Informatics Centre. The campaign's infrastructure relies on a single command and control server with multiple domains, including hijacked healthcare domains. The investigation revealed a toolkit comprising various remote access tools, credential harvesting tools, and exploit tooling for CVE-2024-6387. TRU assesses with moderate confidence that this campaign is linked to the APT36 (Transparent Tribe) group, indicating an evolution in their targeting and operational tactics. The campaign reflects a shift towards Afghan telecom providers and critical sectors like government and energy. The investigation began after discovering a malicious ZIP archive on VirusTotal in June 2026.
Key Points: • PATCHCORD is a new malware targeting Afghan telecom and South Asian infrastructure. • The malware is delivered via fake VPN installers and includes a Go-based implant for C2. • The campaign is linked to the APT36 group, indicating a shift in their operational focus.