Introduction
Acronis
Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD's capabilities while abusing Google Sheets for C2 communication. The malware was actively distributed through a domain impersonating India's National Informatics Centre (NIC).
Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through...
www.acronis.com
The campaign's infrastructure centers on a single C2 server with multiple associated domains, including domains impersonating Afghan telecom operators and a hijacked legitimate healthcare domain. An exposed staging server revealed the operator's broader toolkit, including SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for
CVE-2024-6387 (regreSSHion). This research details TRU's analysis of the PATCHCORD, SHEETCORD and HACKERAI C2 Agent malware families, their C2 mechanisms and the supporting infrastructure.
TRU assesses with moderate confidence that the campaign overlaps with the APT36 (
Transparent Tribe) cluster based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft.
The campaign reflects an evolution of Transparent Tribe's recent operations. While the group has historically focused on government, military and diplomatic organizations in India and the broader South Asian region, our investigation identified a stronger operational focus on Afghan telecom providers alongside government, defense and energy organizations. Combined with three previously undocumented malware families and the use of Google Sheets and GitHub Gists for C2, the campaign demonstrates continued evolution in both the group's targeting priorities and operational tradecraft.
Telecom providers remain particularly attractive targets for espionage actors because they provide access to communications infrastructure, subscriber information and government communications, enabling intelligence collection that extends well beyond a single organization.