< Back to all clusters
[TECHNOLOGY] · Afghanistan, India · 2 sources

started · updated

PATCHCORD espionage campaign targets Afghan telecom and South Asian infrastructure

Acronis researchers have identified a stealthy espionage campaign, dubbed PATCHCORD, targeting Afghan telecommunications providers and critical infrastructure in South Asia. The operation utilizes a custom C/C++ backdoor delivered through highly specific lures, such as fake VPN installers that impersonate Afghan Telecom (AFTEL) and various telecom management tools.

As part of the infrastructure pivoting, researchers discovered SHEETCORD, a Go-based implant that leverages Google Sheets for command-and-control (C2) communication. This malware was distributed via a domain impersonating India’s National Informatics Centre (NIC). The attackers employ sophisticated persistence techniques, including hijacking shortcut files for major web browsers like Edge, Chrome, and Firefox to maintain access.

Entities

APT36 · Acronis · Afghan Telecom · Google · National Informatics Centre