Adversary Intelligence — 2026-08-17

APT36 Transparent Tribe Deploys Previously Undocumented PATCHCORD Backdoor Against Afghan Telecom and South Asian Infrastructure

BLUFAPT36's pivot to cloud-API command channels renders domain-based network defenses across Afghan telecom and Indian government infrastructure functionally blind to ongoing collection operations.

Acronis Threat Research Unit identified a previously undocumented backdoor, PATCHCORD, a compiled C/C++ implant targeting Afghan telecom providers and South Asian critical infrastructure via fake VPN installers impersonating Afghan Telecom (AFTEL) 123. The implant hijacks browser shortcuts for Edge, Chrome and Firefox to maintain persistence and communicates with a C2 server at 46.30.188.13 12. Infrastructure pivoting identified two additional implants: SHEETCORD, a Go-based backdoor using the Google Sheets API for C2 and delivered via a domain impersonating India's National Informatics Centre, and HACKERAI C2 Agent, a GitHub Gists-based C2 tool bearing hallmarks of AI-assisted development including a hardcoded GitHub access token and duplicated XOR routines 123. An exposed staging server tied to the operator held the SuperShell C2 framework, additional RAT and credential-harvesting tools, and exploit code for CVE-2024-6387 124. Acronis assesses with moderate confidence that the campaign overlaps with APT36 (Transparent Tribe), citing shared credential-harvesting tools, an independently attributed C2 framework, and a similar Google Sheets C2 technique from an earlier APT36 campaign 123.

Analysis
Acronis Threat Research Unit assesses with moderate confidence, based on shared credential-harvesting tools, an independently attributed C2 framework, and a Google Sheets C2 technique matching an earlier APT36 campaign, that the operator overlaps with Transparent Tribe, though the same infrastructure signature could equally indicate a commercial access broker serving multiple Pakistan-aligned operators. Routing SHEETCORD and HACKERAI C2 through Google Sheets and GitHub Gists defeats domain and IP blocklisting that Afghan telecom and Indian government defenders rely on, while browser-shortcut hijacking persists past cleanups targeting the registry Run key alone. The exposed staging server gives responders a rare pre-emptive window to build detections for SuperShell, the regreSSHion exploit chain, and the credential harvesters before the next lure cycle. Security Affairs, The Hacker News, and GBHackers merely reproduce Acronis's findings, leaving the assessment resting on one research team's infrastructure pivoting.
4 sources
  1. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure - Acronis Threat Research Unit
  2. New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure - The Hacker News
  3. APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2 - Security Affairs
  4. PATCHCORD Infrastructure Hosts SuperShell C2 for Remote Commands and Webshell Management - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE