Afghan Telecom TMS request portal
At a glance
| Actor/Group | APT36 / Transparent Tribe (moderate confidence) |
| Activity Type | Cyber espionage; custom backdoor delivery via fake installers |
| Targets | Afghan telecom providers; Indian government, defense, and energy organizations |
| Scale | Not officially disclosed; one C2 server tied to multiple campaigns since December 2025 |
| Jurisdiction / Law Enforcement Status | No law enforcement action reported; findings come from private security research |
| Source | Acronis Threat Research Unit (TRU) |
Acronis researchers uncovered a new malware cluster hitting Afghan telecom firms. This PATCHCORD malware APT36 campaign also strikes Indian government, defense, and energy targets. Researchers assess the APT36 link with moderate confidence, based on shared tools and targeting patterns.
What Happened
PATCHCORD Arrives Through a Fake VPN Installer
The campaign starts with a fake Afghan Telecom VPN installer. Once run, it drops PATCHCORD, a C++ backdoor that hides its console window. The malware then hijacks browser shortcuts for Edge, Chrome, and Firefox. So, each hijacked shortcut launches the real browser first. Users notice nothing wrong. In the background, PATCHCORD registers with its command server and waits for tasking. Also, the implant can adjust its beacon timing and list running processes. It can also run shellcode in memory, execute shell commands, and control its own persistence.
SHEETCORD Abuses Google Sheets for Command and Control
A second implant, SHEETCORD, showed up in a fake Ministry of Defense update. Written in Go, it reuses much of PATCHCORD’s design. But it swaps the custom C2 server for the Google Sheets API. Each victim gets its own tab in the operator’s spreadsheet. That tab handles both tasking and stolen data. SHEETCORD also adds a new persistence trick: a VBScript file that launches at every logon. And it expands shortcut hijacking to six browsers instead of three.
HACKERAI: A Third C2 Channel Built with AI Help
The oldest domain in the cluster served a third tool, HACKERAI C2 Agent. Meanwhile, code comments and leftover test strings suggest AI-assisted development. This implant swaps Google Sheets for GitHub Gists to move tasking and stolen data. It shares fingerprinting and shell-execution features with PATCHCORD and SHEETCORD. So, all three tools form one connected family.
A Widening Web of Fake Domains
Domain pivoting revealed a much wider web of fake fronts. Everything traces back to one server at 46.30.188.13, hosted in the Netherlands. Also, the group even hijacked a real healthcare domain to help host the network. The earliest domain, appstoore[.]solutions, went live in January 2026 and became PATCHCORD’s hardcoded C2 address. Over the next six months, the group added new fronts one by one. Afghantelecom[.]site appeared in May 2026, directly copying the real Afghan Telecom name. Caprispine[.]health, also from May, copied a real Delhi clinic instead. Then came afghanistanupdates[.]site and servicesindia[.]services in June, followed by nic-support[.]site in July. That last domain now serves SHEETCORD to targets inside India’s Ministry of Defense. A separate March 2026 campaign used yet another PATCHCORD variant, hidden inside a fake NHPC Fuel Conservation Client. That version added checks for virtual machines, debuggers, and tools like Wireshark, so it could dodge sandbox testing.
Who Is Behind It
Acronis TRU links the campaign to APT36, widely tracked as Transparent Tribe. In its report, the team said it “assesses with moderate confidence that the campaign overlaps with the APT36 cluster.” That confidence rests on four points. First, the lures target Afghan Telecom and Indian government bodies, matching APT36’s known focus. Second, the group’s server hosted HackBrowserData, a credential tool seen in past APT36 attacks on Indian Air Force staff. Third, the same server held GateSentinel, a C2 framework tied to APT36 by other researchers. Fourth, SHEETCORD’s Google Sheets technique closely matches an earlier campaign called SHEETCREEP, also linked to the group. The staging server also matched a SuperShell fingerprint tied to a separate group called SilverFox. Acronis found no proof the two groups worked together, so that overlap does not change the APT36 assessment. Still, this stays a moderate-confidence call, not a confirmed link.
Impact and Scale
The exposed staging server hints at a much bigger operation. In addition, it held SuperShell, Metasploit, and several Python-based C2 listeners. It also held exploit code for CVE-2024-6387 and CVE-2021-4034, two known Linux flaws. Files with names like Routers_backup.zip and an iOS call-history record suggest the group hit network gear and mobile devices too. Acronis has not confirmed how many victims fell to this PATCHCORD malware APT36 campaign, or what data left their networks. Telecom firms make prime targets for spies. Acronis notes this access can expose networks and subscriber data. That kind of access can fuel much wider spying efforts.
What Comes Next
Acronis says the network remains active as of this report. So, the group keeps rotating domains, and new lures will likely follow. Groups in South Asia should watch for fake VPN or update installers. Watch especially for ones tied to telecom or government branding. IT teams should also patch the regreSSHion flaw, tracked as CVE-2024-6387. The group’s toolkit targets this exact bug directly. Also, checking browser shortcuts for unexpected targets can catch this style of persistence early. Finally, security teams should monitor traffic to Google Sheets and GitHub Gists. Both now double as covert channels for this kind of campaign. The PATCHCORD malware APT36 story is far from over.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.