Executive Summary
In August 2026, a cyber espionage campaign attributed to the Pakistan-aligned threat actor APT36 (Transparent Tribe) targeted Afghan telecom providers and South Asian critical infrastructure. The attackers deployed a previously undocumented backdoor named PATCHCORD, delivered through sector-specific lures such as fake VPN installers impersonating Afghan Telecom. PATCHCORD establishes persistence by hijacking browser shortcuts and communicates with a command-and-control server to execute arbitrary commands, enumerate processes, and deploy additional payloads. The campaign also introduced SHEETCORD, a Go-based backdoor utilizing Google Sheets for command-and-control, delivered via domains impersonating India's National Informatics Center. This incident underscores the evolving tactics of APT36, highlighting their focus on critical infrastructure and the use of sophisticated malware to maintain long-term access and exfiltrate sensitive information. Organizations in the region should enhance their cybersecurity measures to detect and mitigate such threats.
Why This Matters Now
The emergence of PATCHCORD and SHEETCORD backdoors signifies a significant escalation in cyber threats targeting critical infrastructure in South Asia. The use of sophisticated malware by APT36 highlights the urgent need for organizations to bolster their cybersecurity defenses to prevent potential data breaches and operational disruptions.
Attack Path Analysis
APT36 initiated the attack by delivering a ZIP archive containing a malicious installer disguised as Afghan Telecom's Transport Management System, leading to the execution of the PATCHCORD backdoor. Upon execution, PATCHCORD concealed its console window and hijacked browser shortcuts to establish persistence, allowing it to maintain access across system reboots. The backdoor then fingerprinted the host and registered with its command-and-control server to receive further instructions. Through the C2 channel, the attackers could execute arbitrary commands, adjust beacon intervals, and deploy additional payloads. The backdoor's capabilities enabled the exfiltration of sensitive data from the compromised systems. The campaign targeted Afghan telecom providers and Indian critical infrastructure, aiming to gather intelligence and potentially disrupt operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
APT36 delivered a ZIP archive containing a malicious installer disguised as Afghan Telecom's Transport Management System, leading to the execution of the PATCHCORD backdoor.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Masquerading
Command and Scripting Interpreter: Windows Command Shell
Application Layer Protocol: Web Protocols
Ingress Tool Transfer
System Information Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Afghan telecom providers directly targeted by PATCHCORD backdoor through fake VPN installers and transport management systems, enabling lateral movement and data exfiltration.
Government Administration
Indian government IT networks compromised via fake NIC websites deploying SHEETCORD backdoor, threatening zero trust segmentation and east-west traffic security controls.
Oil/Energy/Solar/Greentech
Energy sector targeted with anti-analysis PATCHCORD variants, exposing critical infrastructure to cyber espionage through encrypted traffic vulnerabilities and egress policy bypass.
Health Care / Life Sciences
Hijacked legitimate healthcare domain used in C2 infrastructure demonstrates threat actor's ability to compromise medical organizations for command and control operations.
Sources
- New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructurehttps://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.htmlVerified
- APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entitieshttps://thehackernews.com/2026/02/apt36-and-sidecopy-launch-cross.htmlVerified
- Transparent Tribe, COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM, Group G0134 | MITRE ATT&CK®https://attack.mitre.org/groups/G0134/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute the PATCHCORD backdoor may have been constrained by enforcing strict identity-based access controls.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to maintain persistent access would likely be constrained by enforcing strict segmentation policies.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained by enforcing east-west traffic controls.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command-and-control channels would likely be constrained by enforcing multicloud visibility and control.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained by enforcing strict egress security policies.
The attacker's ability to disrupt operations and gather intelligence would likely be constrained by limiting unauthorized access and data exfiltration.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Data Management
- Service Provisioning
- Billing Systems
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of customer personal information, call records, and internal operational data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced threat detection systems to identify and block malicious payloads during the initial compromise phase.
- • Enforce strict application control policies to prevent unauthorized software execution and persistence mechanisms.
- • Utilize network segmentation and access controls to limit lateral movement within the network.
- • Monitor and analyze network traffic for unusual patterns indicative of command-and-control communications.
- • Establish robust data loss prevention measures to detect and prevent unauthorized data exfiltration.



