PATCHCORD is a custom Windows backdoor used in an ongoing cyber-espionage campaign targeting Afghan telecom providers and broader South Asian government, defense, energy, and critical infrastructure organizations. The activity has been linked with moderate confidence to APT36, also known as Transparent Tribe, based on overlaps in targeting, infrastructure, malware design, and operational tradecraft.
The malware is a compiled C/C++ implant delivered through highly tailored social-engineering lures, including fake VPN installers and telecom management software themed to impersonate legitimate regional entities. After execution, PATCHCORD establishes persistence primarily by hijacking browser shortcuts so that the malware launches before the legitimate browser while still opening the expected application to reduce user suspicion. Reported targets for this shortcut hijacking include Microsoft Edge, Google Chrome, and Mozilla Firefox. It also uses a Windows Run key to maintain execution across reboots and to trigger its browser-hijacking routine at user logon.
PATCHCORD fingerprints infected hosts and communicates with command-and-control infrastructure to receive tasking. Its supported functionality includes adjusting beacon timing, enumerating running processes, executing arbitrary system commands through a hidden shell, and decoding, decrypting, and running shellcode entirely in memory. This in-memory execution reduces disk artifacts and supports stealthier post-compromise activity. Variants observed in related operations also incorporated anti-analysis and anti-debugging checks.
PATCHCORD appears to be the primary implant in a broader malware ecosystem that also includes the Go-based SHEETCORD backdoor and HACKERAI C2 Agent, which shift command-and-control traffic to cloud services such as Google Sheets and GitHub Gists. The campaign reflects a sustained espionage focus on telecommunications and state-linked sectors across South Asia, with particular emphasis on Afghan telecom-related targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An exposed staging server revealed the operator's broader toolkit, including SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387 (regreSSHion). | The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Acronis researchers have uncovered a sophisticated espionage campaign involving a new backdoor named PATCHCORD, which is targeting Afghan telecom providers and critical infrastructure in South Asia through deceptive fake VPN tools.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
targeting Afghan telecom providers and critical infrastructure in South Asia through deceptive fake VPN tools. This campaign utilizes highly specific lures, including fake installers that impersonate legitimate companies like Afghan Telecom
The implant receives an encoded payload as part of the tasking response, decodes it using the same custom Base64 alphabet and decrypts it using a XOR-based routine with a key derived from the session context.
a variant of the backdoor that features anti-analysis and anti-debugging techniques to sidestep detection
Once active, it communicates with command and control (C2) servers, capable of listing processes
fingerprints the host... The backdoor implements a remote command execution capability through PowerShell instead of "cmd.exe," gathers basic host information
registers with its C2 server ("46.30.188[.]13") to receive tasking commands... uses Google Sheets for command-and-control (C2) communications... uses GitHub Gists for C2
registers with its C2 server ("46.30.188[.]13") to receive tasking commands
The threat actor deployed PATCHCORD, SHEETCORD, and HACKERAI C2 Agent, transitioning from a custom C/C++ backdoor to Go-based implants that abuse Google Sheets and GitHub Gists for covert command-and-control.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used in an espionage campaign that targets Afghan telecom providers and critical infrastructure via fake VPN installers. It persists by hijacking browser shortcuts for Edge, Chrome, and Firefox, then communicates with C2 servers to list processes, execute shellcode in memory, and run arbitrary commands.
A previously undocumented custom C/C++ backdoor/implant delivered via fake VPN installers and telecom management tools. It establishes persistence by hijacking browser shortcuts, checks in with a C2 server, and supports beacon interval changes, process listing, in-memory shellcode execution, hidden-shell command execution, and remote control of its persistence mechanism.
A malware cluster/backdoor used in an active cyber espionage campaign by APT36/Transparent Tribe, with newer Go-based implants using cloud services for covert command-and-control.
The main implant in the broader campaign. It establishes persistence by hijacking browser shortcuts and uses attacker infrastructure for command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.