Acronis Threat Research Unit tied the long-running persistent threat group to another campaign aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD.
PATCHCORD
PATCHCORD is a custom compiled C/C++ Windows backdoor used in an ongoing cyber-espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia.
Profile source: Mallory opens in a new tabPATCHCORD
Family profile
PATCHCORD is a custom compiled C/C++ Windows backdoor used in an ongoing cyber-espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia. The activity has been linked with moderate confidence to the Pakistan-aligned Transparent Tribe, also tracked as APT36. It is delivered through sector-specific phishing and social-engineering lures, including fraudulent VPN installers impersonating Afghan Telecom and purported telecommunications-management software.
PATCHCORD fingerprints infected hosts, enumerates running processes, communicates with command-and-control infrastructure, adjusts its beaconing interval, and executes arbitrary shell commands. It can decode, decrypt, and execute shellcode in memory, reducing payload artifacts on disk. The implant employs browser-shortcut hijacking for persistence, modifying shortcuts for common browsers so that PATCHCORD runs before the legitimate browser while continuing to launch the intended application to reduce user suspicion. Variants have also used a Windows Run-key persistence mechanism. A variant used against India’s energy sector incorporated virtual-machine, sandbox, debugger, security-tool, and low-resource-environment checks.
Capabilities
- Defense Evasion
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
2 named in public reportingThis year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called "Patchcord" and "Sheetcord."
Exploited software
Vulnerabilities linked to PATCHCORD
1 CVEsMITRE ATT&CK
PATCHCORD in ATT&CK
22 distinct techniquesTechniques
22 techniquesReporting
Research mentioning PATCHCORD
PATCHCORD: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure | Community Portal | Gurucul
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.