The recent campaign targeting Afghan telecom providers and South Asian critical infrastructure organizations has introduced a new backdoor called PATCHCORD. This backdoor is a compiled C/C++ implant, delivered through sector-specific lures such as fake VPN installers that impersonate Afghan Telecom (AFTEL) and telecom management tools. The campaign's infrastructure also includes another Go-based backdoor named SHEETCORD, which uses Google Sheets for command-and-control (C2) communications, and is delivered via a domain impersonating India's National Informatics Center (NIC). The infrastructure supporting this campaign revolves around a single C2 server connected to multiple domains, including those impersonating Afghan telecom operators and a hijacked legitimate healthcare domain. Researchers Darrel Virtusio, Santiago Pontiroli, and Subhajeet Singha have attributed this activity to a threat actor known as APT36 (aka Transparent Tribe) with moderate confidence, based on overlaps in targeting patterns, malware similarities, shared infrastructure, and operational tradecraft. The attack begins with a ZIP archive named "Telecom_TMS.zip," containing an Inno Setup installer ("TMS_AfghanTelecom.exe") that delivers PATCHCORD. This installer is associated with Afghan Telecom's Transport Management System, used for tracking corporate vehicle and transport requests. Once executed, the backdoor conceals its console window, establishes persistence by hijacking browser shortcuts, fingerprints the host, and registers with its C2 server to receive tasking commands. PATCHCORD's capabilities include adjusting the C2 beacon interval, enumerating running processes, decoding and executing shellcode payloads, executing arbitrary commands via "cmd.exe," and providing interactive control over the browser shortcut hijacking persistence mechanism. When launched through a hijacked browser shortcut, it starts the legitimate browser before continuing its execution in the background, maintaining user experience while ensuring persistence. The implant checks for a Windows Registry value named "BeaconBrowserHijack" to determine if the system is already compromised. If not, it writes its executable path to the Windows Registry key, establishing persistence across reboots and activating the browser shortcut hijacking routine whenever the user logs into Windows. The campaign also targets Indian government IT networks with a fake NIC website to deploy SHEETCORD, which combines functionalities from both SHEETCREEP and PATCHCORD. SHEETCORD implements remote command execution through PowerShell, gathers basic host information, and uses the Windows Startup folder for persistence. It also incorporates PATCHCORD's browser shortcut hijacking mechanism to target additional browsers like Brave, Opera, and Vivaldi, and uses the Google Sheets API for C2 communication. PATCHCORD has been used by the threat actor since at least March 2026, including attacks on India's energy sector with variants featuring anti-analysis and anti-debugging techniques. An exposed staging server linked to the threat actor has provided insights into their evolving toolkit, which includes open-source C2 frameworks like antnium, GateSentinel, and SuperShell, exploits for CVE-2024-6387, AI-assisted malware projects, and campaign-specific files. One AI-assisted project, HACKERAI C2, overlaps with PATCHCORD and SHEETCORD, using GitHub Gists for C2 and offering dedicated upload and download functionalities for tasking and data exfiltration. This campaign reflects an evolution in Transparent Tribe's operations, with a stronger focus on Afghan telecom providers alongside government, defense, and energy organizations. The use of three previously undocumented malware families and innovative C2 methods like Google Sheets and GitHub Gists demonstrates the group's continued evolution in targeting priorities and operational tradecraft.
Cybercrime
New Backdoor Targets Afghan Telecom and Critical Indian Infrastructure
Cyber RTAugust 16, 20263 min read

A new cyber campaign targets Afghan telecom providers and South Asian infrastructure, deploying a backdoor named PATCHCORD. Delivered via fake VPN installers, it uses browser shortcut hijacking for persistence. Another backdoor, SHEETCORD, employs Google Sheets for command-and-control. Linked to APT36, the campaign also targets Indian IT networks. The threat actor's evolving toolkit includes AI-assisted malware and open-source C2 frameworks, reflecting a shift in targeting priorities.


