< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-13T20:30:29+05:30

Advanced PATCHCORD Backdoor Exploits Afghan Telecom and Indian Critical Infrastructure

A new backdoor named PATCHCORD, linked to the APT36 threat group, targets Afghan telecom providers and Indian critical infrastructure through spoofed telecom tools and Google Sheets-based C2 communications. The campaign employs sophisticated persistence mechanisms and overlaps with another backdoor, SHEETCORD, demonstrating evolving cyber espionage tactics.

Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD.

According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (

Read original article

*** END OF TRANSMISSION ***