PATCHCORD Backdoor Spearheads South Asian Cyberespionage
Security specialists at Acronis uncovered an active cyberespionage campaign targeting telecommunications companies in Afghanistan. Furthermore, the attackers focus heavily on government agencies and critical infrastructure facilities across South Asia. To execute these attacks, threat actors created multiple previously unknown malware variants, notably the PATCHCORD backdoor.
At a glance: Infection Chain and Propagation
The investigation formally commenced in June 2026. At that time, researchers discovered a highly suspicious ZIP archive named Telecom_TMS uploaded directly to VirusTotal. This archive contained a malicious installer carefully disguised as legitimate Afghan Telecom software. Crucially, the file properties fraudulently displayed the telecom operator’s name. Moreover, the publisher link redirected victims to the company’s genuine web portal. When a user executed the installer, it silently deployed the PATCHCORD backdoor onto their system.
Unconventional Persistence via Browser Shortcuts
This malicious program establishes persistence within Windows using a highly unconventional method. Specifically, PATCHCORD maliciously alters the standard desktop shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox. Consequently, launching the browser executes the backdoor first, followed immediately by the legitimate browser application. The visual icon and the expected behavior of the shortcut remain completely unchanged. Therefore, the average user typically notices absolutely nothing suspicious. Additionally, the program solidifies its presence by adding itself directly to the Windows registry startup section.
Data Theft and Command Execution Capabilities
After successfully infecting a system, PATCHCORD aggressively harvests the computer name, current user details, and specific Windows version information. It also gathers comprehensive process data before initiating contact with its command-and-control server. The remote operator can secretly monitor all running processes and execute arbitrary system commands. Critically, the attacker can also launch supplementary malicious code directly within the system’s RAM, leaving no forensic footprint on the hard drive.
SHEETCORD: Abusing Google Sheets for C2
Further investigation led security specialists to discover another malicious program dubbed SHEETCORD, written entirely in Go. Attackers distributed this malware from a fraudulent website impersonating the National Informatics Centre of India. Incredibly, this specific program abuses Google Sheets to receive commands and exfiltrate stolen data. The malware creates a unique, dedicated spreadsheet tab for every newly infected machine. Furthermore, SHEETCORD expands the shortcut hijacking technique to target six different browsers, including Brave, Opera, and Vivaldi.
Broadening the Attack Surface: Infrastructure and AI Tools
The attackers utilized this connected infrastructure to launch devastating attacks against the Indian energy sector. On an exposed intermediary server, specialists discovered tools specifically designed to exploit CVE-2024-6387 in OpenSSH and CVE-2021-4034 in Linux. They also found aggressive password brute-forcing utilities, Metasploit frameworks, SuperShell instances, and specialized programs designed to steal browser data. Additionally, researchers uncovered files indicating the attackers likely stole sensitive data from network equipment and mobile devices.
HACKERAI C2 Agent: The Role of LLMs
Researchers also discovered a component named the HACKERAI C2 Agent. Acronis analysts strongly suspect developers created this agent using programming tools based entirely on large language models. They base this conclusion on the specific code structure, lingering developer comments, and residual debugging messages. Interestingly, to exchange commands covertly, the HACKERAI C2 Agent utilizes GitHub Gists instead of a dedicated server or Google Sheets.
Attribution and Ongoing Threat Assessment
Acronis currently assesses with moderate confidence that this extensive campaign is intrinsically linked to APT36. Security researchers also widely know this group as Transparent Tribe. Alternatively, it might involve a closely aligned, Pakistan-nexus threat group. The specific targeting choices strongly suggest this connection. Furthermore, the striking similarities in the custom malware, the shared infrastructure, and the specific tools utilized align closely with previously observed APT36 operations. At the time of the report’s publication, the malicious infrastructure supporting this campaign remained fully operational.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.