PATCHCORD is a Windows backdoor used in a South Asia-focused cyber espionage campaign assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked actor. The malware has been used against telecommunications, government, defense, energy, and other critical infrastructure organizations, with notable targeting themed around Afghan telecom entities and Indian government-related lures.
PATCHCORD is implemented as a compiled C/C++ implant and has been delivered through sector-specific fake software installers and related lure material. Once executed, it establishes persistence through browser shortcut hijacking and Windows Run key mechanisms. Its shortcut hijacking targets major browsers while preserving normal browser launch behavior and appearance, allowing the implant to start before the legitimate application and reducing user suspicion.
Functionally, PATCHCORD performs host fingerprinting and maintains command-and-control communications over HTTP. Reported capabilities include victim registration, configurable beaconing, process enumeration, remote shell execution, and in-memory shellcode execution without writing the payload to disk. Variants have also incorporated anti-analysis checks aimed at virtualized, sandboxed, debugged, or otherwise instrumented environments, indicating an emphasis on defense evasion.
PATCHCORD appears to serve as a primary implant within a broader malware ecosystem that also includes SHEETCORD and HACKERAI C2 Agent, reflecting an evolving espionage toolkit that combines traditional backdoor functionality with covert persistence and operator-controlled post-exploitation actions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An exposed staging server revealed the operator's broader toolkit, including SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387 (regreSSHion). | The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
If not found, it writes its own executable path to this key, establishing persistence across reboots... SHEETCORD also introduces an additional persistence mechanism... drops a VBScript file named SystemHelper.vbs into the Windows Startup folder... It then adds a registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
If not found, it writes its own executable path to this key, establishing persistence across reboots... SHEETCORD also introduces an additional persistence mechanism... drops a VBScript file named SystemHelper.vbs into the Windows Startup folder... It then adds a registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
The implant receives an encoded payload as part of the tasking response, decodes it using the same custom Base64 alphabet and decrypts it using a XOR-based routine with a key derived from the session context.
The installer contains version metadata designed to impersonate Afghan Telecom, with the CompanyName, FileDescription, and ProductName fields set to "Afghan Telecom," "TMS Afghan Telecom Setup," and "TMS Afghan Telecom," respectively.
The implant checks for VirtualBox and VMware device handles... verifies the system has more than one processor and at least 2GB of RAM... scans active TCP connections for ports commonly associated with analysis tools... monitors cursor movement and user input to detect automated sandbox environments. If any check is triggered, the implant enters a randomized sleep loop of 30 to 90 seconds.
PATCHCORD supports five primary tasking operations... 0x1B (27) Process enumeration Enumerates all running processes on the victim's system and returns a JSON report with process name, PID, and full executable path.
The implant fingerprints the victim system by collecting the hostname, username, operating system version, process identifier, executable path and process name before constructing a JSON registration payload for the C2 server.
The implant checks for VirtualBox and VMware device handles... verifies the system has more than one processor and at least 2GB of RAM... scans active TCP connections for ports commonly associated with analysis tools... monitors cursor movement and user input to detect automated sandbox environments. If any check is triggered, the implant enters a randomized sleep loop of 30 to 90 seconds.
The threat actor deployed PATCHCORD, SHEETCORD, and HACKERAI C2 Agent, transitioning from a custom C/C++ backdoor to Go-based implants that abuse Google Sheets and GitHub Gists for covert command-and-control.
The registration payload is sent as an HTTP POST request to the root path of the C2 server... the implant enters a polling loop, sending GET requests to the constructed /api.jsp tasking URL at regular intervals.
The threat actor deployed PATCHCORD, SHEETCORD, and HACKERAI C2 Agent, transitioning from a custom C/C++ backdoor to Go-based implants that abuse Google Sheets and GitHub Gists for covert command-and-control.
Infrastructure analysis also identified artifacts associated with the Metasploit and SuperShell C2 frameworks on the same server. This suggests the operator may leverage these frameworks to generate shellcode payloads delivered through PATCHCORD's in-memory execution capability.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware cluster/backdoor used in an active cyber espionage campaign by APT36/Transparent Tribe, with newer Go-based implants using cloud services for covert command-and-control.
The main implant in the broader campaign. It establishes persistence by hijacking browser shortcuts and uses attacker infrastructure for command-and-control.
A custom C/C++ backdoor/implant for Windows that establishes persistence via browser shortcut hijacking and a Run key, fingerprints the host, registers with an HTTP C2 server, polls for tasks, enumerates processes, executes arbitrary shell commands, and runs shellcode fully in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.