Executive Summary

In August 2026, a cyber espionage campaign attributed to the Pakistan-aligned threat actor APT36 (Transparent Tribe) targeted Afghan telecom providers and South Asian critical infrastructure. The attackers deployed a previously undocumented backdoor named PATCHCORD, delivered through sector-specific lures such as fake VPN installers impersonating Afghan Telecom. PATCHCORD establishes persistence by hijacking browser shortcuts and communicates with a command-and-control server to execute arbitrary commands, enumerate processes, and deploy additional payloads. The campaign also introduced SHEETCORD, a Go-based backdoor utilizing Google Sheets for command-and-control, delivered via domains impersonating India's National Informatics Center. This incident underscores the evolving tactics of APT36, highlighting their focus on critical infrastructure and the use of sophisticated malware to maintain long-term access and exfiltrate sensitive information. Organizations in the region should enhance their cybersecurity measures to detect and mitigate such threats.

Why This Matters Now

The emergence of PATCHCORD and SHEETCORD backdoors signifies a significant escalation in cyber threats targeting critical infrastructure in South Asia. The use of sophisticated malware by APT36 highlights the urgent need for organizations to bolster their cybersecurity defenses to prevent potential data breaches and operational disruptions.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

PATCHCORD is a previously undocumented backdoor deployed by APT36, delivered through fake VPN installers impersonating Afghan Telecom, enabling attackers to execute commands and maintain persistence on compromised systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to execute the PATCHCORD backdoor may have been constrained by enforcing strict identity-based access controls.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to maintain persistent access would likely be constrained by enforcing strict segmentation policies.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the network would likely be constrained by enforcing east-west traffic controls.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish and maintain command-and-control channels would likely be constrained by enforcing multicloud visibility and control.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained by enforcing strict egress security policies.

Impact (Mitigations)

The attacker's ability to disrupt operations and gather intelligence would likely be constrained by limiting unauthorized access and data exfiltration.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • Customer Data Management
  • Service Provisioning
  • Billing Systems
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of customer personal information, call records, and internal operational data.

Recommended Actions

  • Implement advanced threat detection systems to identify and block malicious payloads during the initial compromise phase.
  • Enforce strict application control policies to prevent unauthorized software execution and persistence mechanisms.
  • Utilize network segmentation and access controls to limit lateral movement within the network.
  • Monitor and analyze network traffic for unusual patterns indicative of command-and-control communications.
  • Establish robust data loss prevention measures to detect and prevent unauthorized data exfiltration.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image