Skip to content

PATCHCORD

PATCHCORD is a custom compiled C/C++ Windows backdoor used in an ongoing cyber-espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia.

Profile source: Mallory opens in a new tab

PATCHCORD

Family profile

PATCHCORD is a custom compiled C/C++ Windows backdoor used in an ongoing cyber-espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia. The activity has been linked with moderate confidence to the Pakistan-aligned Transparent Tribe, also tracked as APT36. It is delivered through sector-specific phishing and social-engineering lures, including fraudulent VPN installers impersonating Afghan Telecom and purported telecommunications-management software.

PATCHCORD fingerprints infected hosts, enumerates running processes, communicates with command-and-control infrastructure, adjusts its beaconing interval, and executes arbitrary shell commands. It can decode, decrypt, and execute shellcode in memory, reducing payload artifacts on disk. The implant employs browser-shortcut hijacking for persistence, modifying shortcuts for common browsers so that PATCHCORD runs before the legitimate browser while continuing to launch the intended application to reduce user suspicion. Variants have also used a Windows Run-key persistence mechanism. A variant used against India’s energy sector incorporated virtual-machine, sandbox, debugger, security-tool, and low-resource-environment checks.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

2 named in public reporting
Transparent Tribe

Acronis Threat Research Unit tied the long-running persistent threat group to another campaign aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD.

APT-36

This year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called "Patchcord" and "Sheetcord."

Exploited software

Vulnerabilities linked to PATCHCORD

1 CVEs

MITRE ATT&CK

PATCHCORD in ATT&CK

22 distinct techniques

Reporting

Research mentioning PATCHCORD

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.