New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure Ravie Lakshmanan Aug 13, 2026 Cyber Espionage / Critical Infrastructure Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD . According to Acronis Threat Research Unit (TRU) , the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. An analysis of the threat actor's infrastructure has also led to the discovery of another Go-based backdoor dubbed SHEETCORD that uses Google Sheets for command-and-control (C2) communications. The malware has been found to be delivered via a domain impersonating India's National Informatics Center (NIC). "The campaign's infrastructure centers on a single C2 server with multiple associated domains, including domains impersonating Afghan telecom operators and a hijacked legitimate healthcare domain," researchers Darrel Virtusio, Santiago Pontiroli, and Subhajeet Singha said in a report shared with The Hacker News. The activity is assessed to be the work of a Pakistan-aligned threat actor known as APT36 (aka Transparent Tribe) with moderate confidence, citing overlaps in targeting patterns, malware similarities, shared infrastructure, and operational tradecraft. The starting point is a ZIP archive named "Telecom_TMS.zip" that contains an Inno Setup installer ("TMS_AfghanTelecom.exe") responsible for delivering PATCHCORD. TMS is short for Transport Management System , an internal system used by Afghan Telecom, a state-owned telecommunications company, to track corporate vehicle and transport requests. Upon execution, the backdoor conceals its console window, sets up persistence by hijacking browser shortcuts associated with Google Chrome, Microsoft Edge, and Mozilla Firefox after checking it's running with elevated privileges, fingerprints the host, and registers with its C2 server ("46.30.188[.]13") to receive tasking commands that allow it to - Adjust C2 beacon interval Enumerate all running processes Decode and decrypt a shellcode payload received from the C2 server and execute it in memory Execute arbitrary commands via "cmd.exe" Provide interactive control over the browser shortcut hijacking persistence mechanism "When launched through a hijacked browser shortcut, it transparently starts the legitimate browser before continuing execution in the background, preserving the expected user experience while maintaining persistence," Acronis said. "Otherwise, it proceeds directly to its primary functionality." The implant also checks for a Windows Registry value named "BeaconBrowserHijack" under "HKCU\Software\Microsoft\Windows\CurrentVersion\Run." If the value already exists, it skips the shortcut hijacking process, assuming the system has already been compromised. Should this not be the case, it writes its own executable path to the Windows Registry key and establishes persistence across reboots to activate the browser shortcut hijacking routine whenever the current user logs into Windows. Further examination of the threat actor infrastructure has uncovered a campaign targeting Indian government IT networks, including a fake website that mimics NIC ("nic-support[.]site") to deploy SHEETCORD, which combines functionality present in SHEETCREEP with those incorporated in PATCHCORD. The backdoor implements a remote command execution capability through PowerShell instead of "cmd.exe," gathers basic host information, and uses the Windows Startup folder to establish persistence using a Visual Basic Script, packs in PATCHCORD's browser shortcut hijacking mechanism to also target Brave, Opera, and Vivaldi, and uses the Google Sheets API for C2. PATCHCORD is said to have been put to use by the threat actor since at least March 2026, with one such attack targeting India's energy sector with a variant of the backdoor that features anti-analysis and anti-debugging techniques to sidestep detection. What's more, an exposed staging server linked to the threat actor has offered insights into their evolving offensive toolkit, including open-source C2 frameworks like antnium , GateSentinel , and SuperShell , exploits for CVE-2024-6387 , AI-assisted malware projects, and campaign-specific files. One such AI-assisted project is HACKERAI C2, which overlaps with PATCHCORD and SHEETCORD but uses GitHub Gists for C2 and implements a dedicated upload and download functionality for both tasking and data exfiltration. "The campaign reflects an evolution of Transparent Tribe's recent operations," Acronis said. "While the group has historically focused on government, military and diplomatic organizations in India and the broader South Asian region, our investigation identified a stronger operational focus on Afghan telecom providers alongside government, defense and energy organizations." "Combined with three previously undocumented malware families and the use of Google Sheets and GitHub Gists for C2, the campaign demonstrates continued evolution in both the group's targeting priorities and operational tradecraft." Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE Afghan Telecom , APT36 , Backdoor , critical infrastructure , cyber espionage , Google Sheets , India , Malware , PATCHCORD , SHEETCORD , Transparent Tribe ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources See How to Stop the Browser-Based Attacks Your Existing Stack Misses [Book a Live Demo] [Webinar] See Where Claude Fits in the SOC and Where It Falls Short at Scale Defend Against One-Click AI Memory Poisoning — Download the Cheat Sheet Benchmark Your Defenses Against 338M+ Attack Simulations — Download the Blue Report 2026