Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New PATCHCORD Backdoor Threatens Afghan and Indian Sectors

New PATCHCORD Backdoor Threatens Afghan and Indian Sectors

Posted on August 18, 2026 By CWS

The cybersecurity landscape faces a new challenge as Afghan telecom providers and critical infrastructure in South Asia become the focus of an emerging cyber campaign. This campaign involves a novel backdoor named PATCHCORD, which has been identified by the Acronis Threat Research Unit (TRU) as a significant threat. The PATCHCORD implant, crafted in C/C++, is disseminated through sector-specific lures such as counterfeit VPN installers mimicking Afghan Telecom (AFTEL) and deceptive telecom management tools.

Discovery of SHEETCORD and Threat Actor Attribution

In addition to PATCHCORD, researchers have unearthed another backdoor, SHEETCORD, which operates with command-and-control (C2) communications via Google Sheets. This malware is distributed through a domain masquerading as India’s National Informatics Center (NIC). The infrastructure supporting these activities revolves around a single C2 server linked to multiple domains, some of which impersonate Afghan telecom entities and a legitimate healthcare domain.

The campaign is tentatively attributed to APT36, also known as Transparent Tribe, a threat group aligned with Pakistan. This attribution is based on shared characteristics in targeting strategies, malware similarities, and operational techniques observed in past attacks.

Mechanism and Persistence of PATCHCORD

The delivery method begins with a ZIP file named “Telecom_TMS.zip,” containing an installer “TMS_AfghanTelecom.exe” that deploys PATCHCORD. This installer exploits an internal Afghan Telecom system used for managing transport requests. Once executed, PATCHCORD operates stealthily by obscuring its console window and establishing persistence through hijacking browser shortcuts associated with popular browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox.

Upon launching via a compromised browser shortcut, PATCHCORD seamlessly initiates the legitimate browser while executing in the background. This allows it to maintain user experience integrity while carrying out its primary functions, such as adjusting C2 beacon intervals and executing arbitrary commands.

Implications and Future Threats

Furthermore, the malware checks for a specific Windows Registry value to ascertain if browser hijacking has already been implemented on the system. If not, it writes its executable path to the registry, ensuring persistence. The threat actor’s infrastructure has also targeted Indian government IT networks, using a false NIC website to distribute SHEETCORD, which incorporates features from both SHEETCREEP and PATCHCORD.

PATCHCORD has been active since at least March 2026, with incidents involving India’s energy sector, where it deployed sophisticated anti-analysis techniques. An exposed staging server has revealed the evolution of the threat actor’s toolkit, including AI-assisted projects and open-source C2 frameworks.

According to Acronis, these operations signify an evolution of Transparent Tribe’s focus, traditionally centered on governmental and military sectors in India and South Asia. The current campaign highlights a shift towards Afghan telecom and critical infrastructure, underscoring the persistent and adaptive nature of these cyber threats.

The Hacker News Tags:Afghan telecom, AI-assisted malware, APT36, Backdoor, C2 servers, cyber threat, Cybersecurity, energy sector, GitHub Gists, Google Sheets, Indian infrastructure, Malware, PATCHCORD, SHEETCORD, Transparent Tribe

Post navigation

Previous Post: Windows 11 Enhances File Explorer with Speedy Menus
Next Post: Critical Security Flaw in GitLab Resolved

Related Posts

Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices The Hacker News
CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems The Hacker News
Boosting MTTR: Key Strategies of Advanced SOCs Boosting MTTR: Key Strategies of Advanced SOCs The Hacker News
Why Organizations Are Turning to RPAM Why Organizations Are Turning to RPAM The Hacker News
Turla Develops Kazuar into Advanced P2P Botnet Turla Develops Kazuar into Advanced P2P Botnet The Hacker News
New Android Malware Wave Hits Banking via NFC Relay Fraud, Call Hijacking, and Root Exploits New Android Malware Wave Hits Banking via NFC Relay Fraud, Call Hijacking, and Root Exploits The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk
  • AmnesiaStealer Exploits macOS Browsers for Remote Control
  • WordPress Plugin Flaw Risks 600,000 Sites with Attacks
  • Critical Security Flaw in GitLab Resolved

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk
  • AmnesiaStealer Exploits macOS Browsers for Remote Control
  • WordPress Plugin Flaw Risks 600,000 Sites with Attacks
  • Critical Security Flaw in GitLab Resolved

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark