Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Apt36's Patchcord: A Sophisticated Espionage Campaign Using Google Sheets C2




Apt36, a sophisticated threat group, has been linked to a new espionage campaign called Patchcord, which uses Google Sheets C2 to deliver a custom backdoor to Afghan telecom providers and South Asian critical infrastructure organizations. The Patchcord campaign is a compilation of previously undocumented malware, including the SHEETCORD and HACKERAI C2 Agent, which abuse legitimate cloud services for command-and-control. The malware uses a sophisticated technique to persist on the victim's system by hijacking browser shortcuts, making it difficult to detect. The report highlights the threat actor's use of generative AI in practice and provides valuable insight into the operator's tooling, campaign development, and operational practices.

  • Apt36, a threat group, has launched a new operation called Patchcord, using Google Sheets C2 to deliver a custom backdoor.
  • The Patchcord backdoor is a compiled C/C++ implant that hijacks browser shortcuts to persist on the victim's system.
  • The malware checks in with its command server and supports five core capabilities, including in-memory shellcode execution.
  • The Patchcord campaign is an evolution of the operator's tooling, using legitimate cloud services for command-and-control.
  • The discovery highlights the operator's use of generative AI in code generation, suggesting AI-assisted coding tools were used.



  • Apt36, a threat group known for its sophisticated espionage campaigns, has been linked to a new operation called Patchcord, which uses Google Sheets C2 to deliver a custom backdoor to Afghan telecom providers and South Asian critical infrastructure organizations. The Patchcord campaign, uncovered by Acronis, is a compilation of previously undocumented malware, including the SHEETCORD and HACKERAI C2 Agent, which abuse legitimate cloud services, such as Google Sheets and GitHub Gists, for command-and-control.

    The Patchcord backdoor is a compiled C/C++ implant that is delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom and telecom management tools. The malware is designed to persist on the victim's system by hijacking browser shortcuts, backing up the originals, and rewriting them to launch the malware first, silently starting the real browser afterward. This technique makes it difficult to detect the malware, as it appears to be a legitimate application.

    The malware checks in with its command server and waits for instructions, supporting five core capabilities: adjusting how often it phones home, listing running processes, executing shellcode entirely in memory, running arbitrary commands through a hidden shell, and controlling its own browser-hijacking persistence remotely. The in-memory shellcode execution is the standout feature, as the payload never touches disk at any point, which keeps forensic evidence to a minimum for anyone investigating after the fact.

    The Patchcord campaign is an evolution of the operator's tooling, from a custom C/C++ backdoor to Go-based implants that abuse legitimate cloud services, including Google Sheets and GitHub Gists, for command-and-control. The exposed staging server and related infrastructure provided valuable insight into the operator's tooling, campaign development, and operational practices, enabling the identification of additional infrastructure and previously undocumented malware.

    The report highlights the threat actor's use of generative AI in practice, not only for some dramatic autonomous hacking campaign, but just as an ordinary coding shortcut. The researcher notes that the implant contains code comments and implementation patterns consistent with AI-assisted code generation, suggesting that the malware was developed, at least in part, using LLM-assisted coding tools.

    The discovery of Patchcord, SHEETCORD, and HACKERAI C2 Agent highlights the operator's continued evolution, from a custom C/C++ backdoor to Go-based implants that abuse legitimate cloud services. The Patchcord campaign demonstrates an ongoing espionage operation targeting telecom, government, defense, and critical infrastructure organizations across South Asia.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Apt36s-Patchcord-A-Sophisticated-Espionage-Campaign-Using-Google-Sheets-C2-ehn.shtml

  • https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html

  • https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html

  • https://cybersecuritynews.com/apt36-hacker-group-attacking-linux-systems/

  • https://dailysecurityreview.com/resources/threat-actors-resources/apt36-hackers-abuse-linux-to-deliver-malware-in-espionage-attacks/

  • https://cybersecuritynews.com/transparent-tribe-hacker-group/

  • https://blog.rankiteo.com/acr1770407517-acronis-cyber-attack-february-2026/


  • Published: Sun Aug 16 03:42:09 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us