Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants.
The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
As of 2026-08-14, reporting stated that the campaign infrastructure remained active and associated phishing operations were ongoing. The actor was also described as continuing to expand its cloud-based command-and-control infrastructure.
In March 2026, the operator used a PATCHCORD variant masquerading as an NHPC Fuel Conservation Client installer to target India’s energy sector. Acronis reported this variant also included anti-analysis checks for virtual machines, debuggers, low-resource environments, analysis ports, security tools, and sandbox-like inactivity.
A Golang-based credential stealer dubbed GoStealer was reported targeting Indian Air Force officials. The disclosure identifies a distinct malware/tooling development and a specific victim set not already reflected in the timeline.
Researchers found an exposed staging server containing phishing archives, credential theft tools, exploit code, and several command-and-control frameworks. They assessed this as evidence the operator was preparing multiple campaigns simultaneously.
The activity was assessed with moderate confidence as overlapping with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked actor. Both references describe the malware cluster as part of an APT36-linked espionage campaign.
Acronis researchers identified a malware framework named HACKERAI C2 Agent that uses GitHub Gists for command-and-control and data exfiltration. The malware can collect system information, execute remote commands, and persist by altering browser shortcuts while still launching the legitimate browser.
Researchers identified SHEETCORD, a Go-based variant that uses Google Sheets for command traffic and extends shortcut hijacking to Brave, Opera, and Vivaldi. The reporting describes this as part of the actor’s shift from a custom C/C++ backdoor to Go-based implants.
The campaign used PATCHCORD as its main implant, with persistence achieved by hijacking browser shortcuts for Edge, Chrome, and Firefox. Researchers also associated command-and-control infrastructure including IP address 46.30.188.13 with the operation.
A broader espionage campaign targeted telecom, government, defense, energy, and critical infrastructure organizations in South Asia, including Afghan telecom-themed lures and Indian targets. Lures included fake telecom files, government updates, and software installers.
Researchers linked HACKERAI distribution to a historical domain impersonating India’s Controller General of Defence Accounts, identified as defence.cdga.site. The domain was used before the newer PATCHCORD campaign emerged.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecommunity.gurucul.com
Open sourcecybersecuritynews.com
Open sourceacronis.com
Open sourcexelemental.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.