This year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called "Patchcord" and "Sheetcord."
PATCHCORD
PATCHCORD is a compiled C/C++ Windows backdoor used in an espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia.
Profile source: Mallory opens in a new tabPATCHCORD
Family profile
PATCHCORD is a compiled C/C++ Windows backdoor used in an espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia. It is delivered through sector-themed social-engineering lures, including fraudulent VPN installers impersonating Afghan Telecom and purported telecommunications-management software. The implant fingerprints compromised hosts, enumerates running processes, communicates with command-and-control infrastructure for tasking, adjusts its beacon interval, and executes arbitrary commands and shellcode in memory. PATCHCORD establishes persistence by modifying browser shortcuts so that it runs before launching the intended Microsoft Edge, Google Chrome, or Mozilla Firefox application; it preserves the legitimate browser launch to reduce suspicion. It also uses a Windows Run-key persistence mechanism and can conceal its console window. Variants have incorporated virtual-machine, sandbox, debugger, security-tool, and low-resource-environment checks. The activity has been assessed with moderate confidence as overlapping with the Pakistan-linked Transparent Tribe (APT36) threat actor.
Capabilities
- Defense Evasion
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
2 named in public reportingThis year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called "Patchcord" and "Sheetcord."
Exploited software
Vulnerabilities linked to PATCHCORD
1 CVEsMITRE ATT&CK
PATCHCORD in ATT&CK
22 distinct techniquesTechniques
22 techniquesReporting
Research mentioning PATCHCORD
PATCHCORD: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure | Community Portal | Gurucul
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.