Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New PATCHCORD Backdoor Threatens Afghan and Indian Sectors

New PATCHCORD Backdoor Threatens Afghan and Indian Sectors

Posted on August 18, 2026 By CWS

The cybersecurity landscape faces a new challenge as Afghan telecom providers and critical infrastructure in South Asia become the focus of an emerging cyber campaign. This campaign involves a novel backdoor named PATCHCORD, which has been identified by the Acronis Threat Research Unit (TRU) as a significant threat. The PATCHCORD implant, crafted in C/C++, is disseminated through sector-specific lures such as counterfeit VPN installers mimicking Afghan Telecom (AFTEL) and deceptive telecom management tools.

Discovery of SHEETCORD and Threat Actor Attribution

In addition to PATCHCORD, researchers have unearthed another backdoor, SHEETCORD, which operates with command-and-control (C2) communications via Google Sheets. This malware is distributed through a domain masquerading as India’s National Informatics Center (NIC). The infrastructure supporting these activities revolves around a single C2 server linked to multiple domains, some of which impersonate Afghan telecom entities and a legitimate healthcare domain.

The campaign is tentatively attributed to APT36, also known as Transparent Tribe, a threat group aligned with Pakistan. This attribution is based on shared characteristics in targeting strategies, malware similarities, and operational techniques observed in past attacks.

Mechanism and Persistence of PATCHCORD

The delivery method begins with a ZIP file named “Telecom_TMS.zip,” containing an installer “TMS_AfghanTelecom.exe” that deploys PATCHCORD. This installer exploits an internal Afghan Telecom system used for managing transport requests. Once executed, PATCHCORD operates stealthily by obscuring its console window and establishing persistence through hijacking browser shortcuts associated with popular browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox.

Upon launching via a compromised browser shortcut, PATCHCORD seamlessly initiates the legitimate browser while executing in the background. This allows it to maintain user experience integrity while carrying out its primary functions, such as adjusting C2 beacon intervals and executing arbitrary commands.

Implications and Future Threats

Furthermore, the malware checks for a specific Windows Registry value to ascertain if browser hijacking has already been implemented on the system. If not, it writes its executable path to the registry, ensuring persistence. The threat actor’s infrastructure has also targeted Indian government IT networks, using a false NIC website to distribute SHEETCORD, which incorporates features from both SHEETCREEP and PATCHCORD.

PATCHCORD has been active since at least March 2026, with incidents involving India’s energy sector, where it deployed sophisticated anti-analysis techniques. An exposed staging server has revealed the evolution of the threat actor’s toolkit, including AI-assisted projects and open-source C2 frameworks.

According to Acronis, these operations signify an evolution of Transparent Tribe’s focus, traditionally centered on governmental and military sectors in India and South Asia. The current campaign highlights a shift towards Afghan telecom and critical infrastructure, underscoring the persistent and adaptive nature of these cyber threats.

The Hacker News Tags:Afghan telecom, AI-assisted malware, APT36, Backdoor, C2 servers, cyber threat, Cybersecurity, energy sector, GitHub Gists, Google Sheets, Indian infrastructure, Malware, PATCHCORD, SHEETCORD, Transparent Tribe

Post navigation

Previous Post: Windows 11 Enhances File Explorer with Speedy Menus
Next Post: Critical Security Flaw in GitLab Resolved

Related Posts

Study Reveals Security Flaws in Free Android VPN Apps Study Reveals Security Flaws in Free Android VPN Apps The Hacker News
Security Flaws in AI Frameworks Expose Sensitive Data Security Flaws in AI Frameworks Expose Sensitive Data The Hacker News
Stock Exchange Executive’s Email Hacked for Months Stock Exchange Executive’s Email Hacked for Months The Hacker News
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens The Hacker News
CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader The Hacker News
Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Plugin Flaw Risks 600,000 Sites with Attacks
  • Critical Security Flaw in GitLab Resolved
  • New PATCHCORD Backdoor Threatens Afghan and Indian Sectors
  • Windows 11 Enhances File Explorer with Speedy Menus
  • Heights Finance Data Breach Affects Over 1.2 Million

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Plugin Flaw Risks 600,000 Sites with Attacks
  • Critical Security Flaw in GitLab Resolved
  • New PATCHCORD Backdoor Threatens Afghan and Indian Sectors
  • Windows 11 Enhances File Explorer with Speedy Menus
  • Heights Finance Data Breach Affects Over 1.2 Million

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark