The cybersecurity landscape faces a new challenge as Afghan telecom providers and critical infrastructure in South Asia become the focus of an emerging cyber campaign. This campaign involves a novel backdoor named PATCHCORD, which has been identified by the Acronis Threat Research Unit (TRU) as a significant threat. The PATCHCORD implant, crafted in C/C++, is disseminated through sector-specific lures such as counterfeit VPN installers mimicking Afghan Telecom (AFTEL) and deceptive telecom management tools.
Discovery of SHEETCORD and Threat Actor Attribution
In addition to PATCHCORD, researchers have unearthed another backdoor, SHEETCORD, which operates with command-and-control (C2) communications via Google Sheets. This malware is distributed through a domain masquerading as India’s National Informatics Center (NIC). The infrastructure supporting these activities revolves around a single C2 server linked to multiple domains, some of which impersonate Afghan telecom entities and a legitimate healthcare domain.
The campaign is tentatively attributed to APT36, also known as Transparent Tribe, a threat group aligned with Pakistan. This attribution is based on shared characteristics in targeting strategies, malware similarities, and operational techniques observed in past attacks.
Mechanism and Persistence of PATCHCORD
The delivery method begins with a ZIP file named “Telecom_TMS.zip,” containing an installer “TMS_AfghanTelecom.exe” that deploys PATCHCORD. This installer exploits an internal Afghan Telecom system used for managing transport requests. Once executed, PATCHCORD operates stealthily by obscuring its console window and establishing persistence through hijacking browser shortcuts associated with popular browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox.
Upon launching via a compromised browser shortcut, PATCHCORD seamlessly initiates the legitimate browser while executing in the background. This allows it to maintain user experience integrity while carrying out its primary functions, such as adjusting C2 beacon intervals and executing arbitrary commands.
Implications and Future Threats
Furthermore, the malware checks for a specific Windows Registry value to ascertain if browser hijacking has already been implemented on the system. If not, it writes its executable path to the registry, ensuring persistence. The threat actor’s infrastructure has also targeted Indian government IT networks, using a false NIC website to distribute SHEETCORD, which incorporates features from both SHEETCREEP and PATCHCORD.
PATCHCORD has been active since at least March 2026, with incidents involving India’s energy sector, where it deployed sophisticated anti-analysis techniques. An exposed staging server has revealed the evolution of the threat actor’s toolkit, including AI-assisted projects and open-source C2 frameworks.
According to Acronis, these operations signify an evolution of Transparent Tribe’s focus, traditionally centered on governmental and military sectors in India and South Asia. The current campaign highlights a shift towards Afghan telecom and critical infrastructure, underscoring the persistent and adaptive nature of these cyber threats.
