PATCHCORD is a custom compiled C/C++ Windows backdoor used in an ongoing cyber-espionage campaign targeting Afghan telecommunications providers and government, defense, energy, and critical-infrastructure organizations across South Asia. The activity has been linked with moderate confidence to the Pakistan-aligned Transparent Tribe, also tracked as APT36. It is delivered through sector-specific phishing and social-engineering lures, including fraudulent VPN installers impersonating Afghan Telecom and purported telecommunications-management software.
PATCHCORD fingerprints infected hosts, enumerates running processes, communicates with command-and-control infrastructure, adjusts its beaconing interval, and executes arbitrary shell commands. It can decode, decrypt, and execute shellcode in memory, reducing payload artifacts on disk. The implant employs browser-shortcut hijacking for persistence, modifying shortcuts for common browsers so that PATCHCORD runs before the legitimate browser while continuing to launch the intended application to reduce user suspicion. Variants have also used a Windows Run-key persistence mechanism. A variant used against India’s energy sector incorporated virtual-machine, sandbox, debugger, security-tool, and low-resource-environment checks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An exposed staging server revealed the operator's broader toolkit, including SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387 (regreSSHion). | The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Acronis Threat Research Unit tied the long-running persistent threat group to another campaign aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD.
This year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called "Patchcord" and "Sheetcord."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Its phishing lures have impersonated network and logistics tools used by a large Afghani telecommunications company, a fuel-conservation tool for India's energy sector, an Indian government employee benefits resource, and so on.
The implant receives an encoded payload as part of the tasking response, decodes it using the same custom Base64 alphabet and decrypts it using a XOR-based routine with a key derived from the session context.
The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
a variant of the backdoor that features anti-analysis and anti-debugging techniques to sidestep detection
A variant of Patchcord first seen in March also implemented a variety of checks for detecting whether it's running in a virtual machine or sandbox environment.
Once active, it communicates with command and control (C2) servers, capable of listing processes
fingerprints the host... The backdoor implements a remote command execution capability through PowerShell instead of "cmd.exe," gathers basic host information
a variant of the backdoor that features anti-analysis and anti-debugging techniques to sidestep detection
registers with its C2 server ("46.30.188[.]13") to receive tasking commands... uses Google Sheets for command-and-control (C2) communications... uses GitHub Gists for C2
registers with its C2 server ("46.30.188[.]13") to receive tasking commands
The threat actor deployed PATCHCORD, SHEETCORD, and HACKERAI C2 Agent, transitioning from a custom C/C++ backdoor to Go-based implants that abuse Google Sheets and GitHub Gists for covert command-and-control.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in a separate Transparent Tribe campaign targeting Afghan telecommunications providers and South Asian critical-infrastructure organizations.
Previously undocumented custom compiled C/C++ backdoor delivered via sector-specific lures, including fake Afghan Telecom VPN installers and telecom-management tools.
A newly documented C++ backdoor/implant used by Transparent Tribe for cyber espionage. It supports host fingerprinting, process enumeration, in-memory arbitrary code execution, anti-analysis checks for virtual machines and sandboxes, and persistence via browser shortcut hijacking.
A backdoor used in an espionage campaign that targets Afghan telecom providers and critical infrastructure via fake VPN installers. It persists by hijacking browser shortcuts for Edge, Chrome, and Firefox, then communicates with C2 servers to list processes, execute shellcode in memory, and run arbitrary commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.