A Pakistani-aligned threat actor tracked as APT36 has deployed two previously undocumented backdoors in a sustained espionage campaign targeting Afghan telecom providers and Indian critical infrastructure organizations, according to Acronis Threat Research Unit.
The campaign delivers a compiled C/C++ implant called PATCHCORD through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. Researchers Darrel Virtusio, Santiago Pontiroli, and Subhajeet Singha linked the activity to APT36, also known as Transparent Tribe, with moderate confidence based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft.
Two New Malware Families
The attack begins with a ZIP archive named Telecom_TMS.zip containing an Inno Setup installer for a fake Transport Management System, an internal tool used by Afghan Telecom to track corporate vehicle and transport requests. Upon execution, PATCHCORD hides its console window, checks for elevated privileges, and establishes persistence by hijacking browser shortcuts for Chrome, Edge, and Firefox.
The backdoor fingerprints the host and registers with its command-and-control server at 46.30.188.13 to receive tasking commands. These include adjusting beacon intervals, enumerating running processes, decoding and executing shellcode in memory, and running arbitrary commands via cmd.exe. When launched through a hijacked shortcut, it transparently starts the legitimate browser before continuing in the background.
A second backdoor, SHEETCORD, is a Go-based implant that uses the Google Sheets API for command-and-control communications. It was found on a fake website impersonating India’s National Informatics Center (nic-support.site). SHEETCORD combines SHEETCREEP functionality with PATCHCORD techniques, uses PowerShell instead of cmd.exe, and establishes persistence through the Windows Startup folder with a Visual Basic Script.
Evolving Infrastructure and AI-Assisted Tools
Analysis of an exposed staging server revealed the threat actor’s expanding toolkit, including open-source C2 frameworks such as antnium, GateSentinel, and SuperShell, exploits for CVE-2024-6387 (an OpenSSH vulnerability), and an AI-assisted malware project called HACKERAI C2 that uses GitHub Gists for C2 communications.
Acronis said PATCHCORD has been in use since at least March 2026, with one variant targeting India’s energy sector featuring anti-analysis and anti-debugging techniques. The campaign infrastructure centers on a single C2 server with multiple associated domains, including ones impersonating Afghan telecom operators and a hijacked legitimate healthcare domain.
The activity reflects a shift in APT36’s traditional targeting priorities. While the group has historically focused on Indian government, military, and diplomatic organizations, the investigation identified a stronger operational focus on Afghan telecom providers alongside government, defense, and energy organizations. The use of Google Sheets and GitHub Gists for C2, combined with three undocumented malware families, demonstrates continued evolution in both targeting and tradecraft.
Sources: Acronis Threat Research Unit; The Hacker News; Broadcom Security
discussion