Skip to content

PATCHCORD

PATCHCORD is a compiled C/C++ Windows backdoor used in an espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia.

Profile source: Mallory opens in a new tab

PATCHCORD

Family profile

PATCHCORD is a compiled C/C++ Windows backdoor used in an espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia. It is delivered through sector-themed social-engineering lures, including fraudulent VPN installers impersonating Afghan Telecom and purported telecommunications-management software. The implant fingerprints compromised hosts, enumerates running processes, communicates with command-and-control infrastructure for tasking, adjusts its beacon interval, and executes arbitrary commands and shellcode in memory. PATCHCORD establishes persistence by modifying browser shortcuts so that it runs before launching the intended Microsoft Edge, Google Chrome, or Mozilla Firefox application; it preserves the legitimate browser launch to reduce suspicion. It also uses a Windows Run-key persistence mechanism and can conceal its console window. Variants have incorporated virtual-machine, sandbox, debugger, security-tool, and low-resource-environment checks. The activity has been assessed with moderate confidence as overlapping with the Pakistan-linked Transparent Tribe (APT36) threat actor.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

2 named in public reporting
Transparent Tribe

This year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called "Patchcord" and "Sheetcord."

APT-36

This year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called "Patchcord" and "Sheetcord."

Exploited software

Vulnerabilities linked to PATCHCORD

1 CVEs

MITRE ATT&CK

PATCHCORD in ATT&CK

22 distinct techniques

Reporting

Research mentioning PATCHCORD

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.