Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 10 hostnames
PATCHCORD is a Windows backdoor used in a South Asia-focused cyber espionage campaign assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked actor.
Profile source: Mallory opens in a new tabPATCHCORD
PATCHCORD is a Windows backdoor used in a South Asia-focused cyber espionage campaign assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked actor. The malware has been used against telecommunications, government, defense, energy, and other critical infrastructure organizations, with notable targeting themed around Afghan telecom entities and Indian government-related lures.
PATCHCORD is implemented as a compiled C/C++ implant and has been delivered through sector-specific fake software installers and related lure material. Once executed, it establishes persistence through browser shortcut hijacking and Windows Run key mechanisms. Its shortcut hijacking targets major browsers while preserving normal browser launch behavior and appearance, allowing the implant to start before the legitimate application and reducing user suspicion.
Functionally, PATCHCORD performs host fingerprinting and maintains command-and-control communications over HTTP. Reported capabilities include victim registration, configurable beaconing, process enumeration, remote shell execution, and in-memory shellcode execution without writing the payload to disk. Variants have also incorporated anti-analysis checks aimed at virtualized, sandboxed, debugged, or otherwise instrumented environments, indicating an emphasis on defense evasion.
PATCHCORD appears to serve as a primary implant within a broader malware ecosystem that also includes SHEETCORD and HACKERAI C2 Agent, reflecting an evolving espionage toolkit that combines traditional backdoor functionality with covert persistence and operator-controlled post-exploitation actions.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
Exploited software
MITRE ATT&CK
Reporting
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.