Ethical Hacking News
A new backdoor campaign, attributed to the Pakistan-aligned threat actor APT36, has been identified by the Acronis Threat Research Unit as a significant threat to the global cybersecurity landscape. The campaign, which targets Afghan Telecom and critical infrastructure organizations in India, utilizes a previously undocumented backdoor called PATCHCORD. This backdoor delivers a range of malicious functionalities and has been found to combine functionality present in SHEETCREEP with those incorporated in PATCHCORD. The campaign reflects an evolution of Transparent Tribe's recent operations, with a stronger operational focus on Afghan telecom providers alongside government, defense, and energy organizations. Stay up-to-date with the latest news and insights on cybersecurity threats by following The Hacker News.
A new backdoor campaign, attributed to APT36 (Transparent Tribe), has been identified as a significant threat to the global cybersecurity landscape, targeting Afghan Telecom and critical infrastructure organizations in India. The campaign utilizes a previously undocumented backdoor called PATCHCORD, delivered via sector-specific lures, and possesses various malicious functionalities. A Go-based backdoor dubbed SHEETCORD, employing Google Sheets for C2 communications, has been discovered, combining functionality with PATCHCORD. The campaign's infrastructure centers on a single C2 server with multiple associated domains, including hijacked legitimate healthcare domains. The backdoor campaign delivers a ZIP archive named \"Telecom_TMS.zip\" containing an Inno Setup installer responsible for delivering PATCHCORD. The implant establishes persistence by hijacking browser shortcuts and registers with its C2 server to receive tasking commands. A campaign targeting Indian government IT networks has been uncovered, featuring a fake website and deploying the SHEETCORD backdoor. PATCHCORD has been used since at least March 2026, with variants targeting India's energy sector and featuring anti-analysis and anti-debugging techniques. The campaign reflects an evolution of Transparent Tribe's operations, with a stronger focus on Afghan telecom providers and government organizations.
The cybersecurity landscape has been abuzz with the revelation of a new backdoor campaign, specifically designed to target Afghan Telecom and critical infrastructure organizations in India. This campaign, attributed to the Pakistan-aligned threat actor APT36, also known as Transparent Tribe, has been identified by the Acronis Threat Research Unit (TRU) as a significant threat to the global cybersecurity landscape.
The campaign, which is believed to have commenced since at least March 2026, utilizes a previously undocumented backdoor called PATCHCORD. This backdoor, delivered via sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools, has been found to possess a range of malicious functionalities, including the ability to adjust C2 beacon interval, enumerate all running processes, decode and decrypt shellcode payload, execute arbitrary commands via "cmd.exe," and provide interactive control over the browser shortcut hijacking persistence mechanism.
Furthermore, the threat actor has been observed to utilize a Go-based backdoor dubbed SHEETCORD, which employs Google Sheets for command-and-control (C2) communications. This backdoor has been discovered to be delivered via a domain impersonating India's National Informatics Center (NIC). The malware has been found to combine functionality present in SHEETCREEP with those incorporated in PATCHCORD.
The campaign's infrastructure centers on a single C2 server with multiple associated domains, including domains impersonating Afghan telecom operators and a hijacked legitimate healthcare domain. The activity is assessed to be the work of a threat actor with moderate confidence, citing overlaps in targeting patterns, malware similarities, shared infrastructure, and operational tradecraft.
The starting point of the backdoor campaign is a ZIP archive named "Telecom_TMS.zip" that contains an Inno Setup installer ("TMS_AfghanTelecom.exe") responsible for delivering PATCHCORD. Upon execution, the backdoor conceals its console window, sets up persistence by hijacking browser shortcuts associated with Google Chrome, Microsoft Edge, and Mozilla Firefox after checking it's running with elevated privileges, fingerprints the host, and registers with its C2 server ("46.30.188[.]13") to receive tasking commands that allow it to execute a range of malicious functionalities.
The implant also checks for a Windows Registry value named "BeaconBrowserHijack" under "HKCU\Software\Microsoft\Windows\CurrentVersion\Run." If the value already exists, it skips the shortcut hijacking process, assuming the system has already been compromised. Should this not be the case, it writes its own executable path to the Windows Registry key and establishes persistence across reboots to activate the browser shortcut hijacking routine whenever the current user logs into Windows.
Further examination of the threat actor's infrastructure has uncovered a campaign targeting Indian government IT networks, including a fake website that mimics NIC ("nic-support[.]site") to deploy SHEETCORD. The backdoor implements a remote command execution capability through PowerShell instead of "cmd.exe," gathers basic host information, and uses the Windows Startup folder to establish persistence using a Visual Basic Script.
PATCHCORD is said to have been put to use by the threat actor since at least March 2026, with one such attack targeting India's energy sector with a variant of the backdoor that features anti-analysis and anti-debugging techniques to sidestep detection. Moreover, an exposed staging server linked to the threat actor has offered insights into their evolving offensive toolkit, including open-source C2 frameworks like antnium, GateSentinel, and SuperShell, exploits for CVE-2024-6387, AI-assisted malware projects, and campaign-specific files.
The campaign reflects an evolution of Transparent Tribe's recent operations, with a stronger operational focus on Afghan telecom providers alongside government, defense, and energy organizations. This marks a significant shift in the group's targeting priorities and operational tradecraft, underscoring the need for robust cybersecurity measures to safeguard against such campaigns.
The Acronis Threat Research Unit has emphasized the importance of continued vigilance and proactive security measures to counter this evolving threat landscape. The discovery of this backdoor campaign serves as a stark reminder of the ever-evolving nature of cybersecurity threats and the need for continuous monitoring and analysis to stay ahead of the threats.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Backdoor-Campaign-Targets-Afghan-Telecom-and-Indian-Critical-Infrastructure-ehn.shtml
https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html
Published: Mon Aug 17 09:54:17 2026 by llama3.2 3B Q4_K_M