PATCHCORD Backdoor: Targeting Afghan Telecom and Indian Critical Infrastructure (2026)

The recent discovery of the PATCHCORD backdoor targeting Afghan telecom providers and South Asian critical infrastructure has raised concerns about the evolving tactics of threat actors. This sophisticated malware, delivered through sector-specific lures, highlights the increasing sophistication of cyber threats. What makes this particularly fascinating is the use of fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools, showcasing the attackers' ability to mimic legitimate software. The PATCHCORD backdoor is a compiled C/C++ implant that sets up persistence by hijacking browser shortcuts associated with Google Chrome, Microsoft Edge, and Mozilla Firefox. It also fingerprints the host and registers with its C2 server to receive tasking commands, allowing it to adjust the C2 beacon interval, enumerate running processes, decode and execute shellcode, and provide interactive control over the browser shortcut hijacking mechanism. This level of control and persistence is concerning, as it enables the malware to remain undetected and perform a range of malicious activities. The SHEETCORD backdoor, discovered in the same campaign, uses Google Sheets for command-and-control (C2) communications and has been delivered via a domain impersonating India's National Informatics Center (NIC). This dual-backdoor approach demonstrates the attackers' ability to adapt and target multiple sectors simultaneously. The activity is assessed to be the work of a Pakistan-aligned threat actor known as APT36 (aka Transparent Tribe), with moderate confidence based on overlapping targeting patterns, malware similarities, shared infrastructure, and operational tradecraft. The starting point for the attack is a ZIP archive named "TelecomTMS.zip" containing an Inno Setup installer that delivers PATCHCORD. This installer, named "TMSAfghanTelecom.exe", is responsible for the initial compromise. The malware's persistence mechanisms, including browser shortcut hijacking and Windows Registry modifications, ensure its longevity on compromised systems. Further examination of the threat actor's infrastructure has revealed a campaign targeting Indian government IT networks, including a fake website that mimics NIC to deploy SHEETCORD. This backdoor combines functionality present in SHEETCREEP with those incorporated in PATCHCORD, showcasing the attackers' ability to repurpose and adapt existing malware. The PATCHCORD backdoor has been in use since at least March 2026, with one attack targeting India's energy sector featuring a variant with anti-analysis and anti-debugging techniques. The exposed staging server linked to the threat actor offers insights into their evolving offensive toolkit, including open-source C2 frameworks, exploits, and AI-assisted malware projects. One such project is HACKERAI C2, which overlaps with PATCHCORD and SHEETCORD but uses GitHub Gists for C2 and implements a dedicated upload and download functionality. The campaign's evolution reflects a shift in the threat actor's operational focus, with a stronger emphasis on Afghan telecom providers alongside government, defense, and energy organizations. This development highlights the dynamic nature of cyber threats and the need for continuous adaptation in cybersecurity strategies. The use of Google Sheets and GitHub Gists for C2 further demonstrates the attackers' resourcefulness and adaptability. In conclusion, the PATCHCORD and SHEETCORD backdoors represent a significant threat to Afghan telecom providers and South Asian critical infrastructure. The attackers' ability to mimic legitimate software, adapt malware, and use advanced persistence mechanisms underscores the importance of staying vigilant and implementing robust cybersecurity measures to protect against these evolving cyber threats.

PATCHCORD Backdoor: Targeting Afghan Telecom and Indian Critical Infrastructure (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Lakeisha Bayer VM

Last Updated:

Views: 6055

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Lakeisha Bayer VM

Birthday: 1997-10-17

Address: Suite 835 34136 Adrian Mountains, Floydton, UT 81036

Phone: +3571527672278

Job: Manufacturing Agent

Hobby: Skimboarding, Photography, Roller skating, Knife making, Paintball, Embroidery, Gunsmithing

Introduction: My name is Lakeisha Bayer VM, I am a brainy, kind, enchanting, healthy, lovely, clean, witty person who loves writing and wants to share my knowledge and understanding with you.