Skip to content

PATCHCORD

PATCHCORD is a Windows backdoor used in a South Asia-focused cyber espionage campaign assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked actor.

Profile source: Mallory opens in a new tab

PATCHCORD

Family profile

PATCHCORD is a Windows backdoor used in a South Asia-focused cyber espionage campaign assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked actor. The malware has been used against telecommunications, government, defense, energy, and other critical infrastructure organizations, with notable targeting themed around Afghan telecom entities and Indian government-related lures.

PATCHCORD is implemented as a compiled C/C++ implant and has been delivered through sector-specific fake software installers and related lure material. Once executed, it establishes persistence through browser shortcut hijacking and Windows Run key mechanisms. Its shortcut hijacking targets major browsers while preserving normal browser launch behavior and appearance, allowing the implant to start before the legitimate application and reducing user suspicion.

Functionally, PATCHCORD performs host fingerprinting and maintains command-and-control communications over HTTP. Reported capabilities include victim registration, configurable beaconing, process enumeration, remote shell execution, and in-memory shellcode execution without writing the payload to disk. Variants have also incorporated anti-analysis checks aimed at virtualized, sandboxed, debugged, or otherwise instrumented environments, indicating an emphasis on defense evasion.

PATCHCORD appears to serve as a primary implant within a broader malware ecosystem that also includes SHEETCORD and HACKERAI C2 Agent, reflecting an evolving espionage toolkit that combines traditional backdoor functionality with covert persistence and operator-controlled post-exploitation actions.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
0 IP / 10 hostnames

Leading locations

  • NL8

Leading providers

  • GWY IT PTY LTD8

Infrastructure traits

  • Hosting 8

Reported operators

Threat actors

1 named in public reporting
Transparent Tribe

The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.

Exploited software

Vulnerabilities linked to PATCHCORD

1 CVEs

MITRE ATT&CK

PATCHCORD in ATT&CK

17 distinct techniques

Reporting

Research mentioning PATCHCORD

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.