logo

PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

ID: 60534145-6ed6-542c-9117-17b5401eaf90

STIX ID: report--60534145-6ed6-542c-9117-17b5401eaf90

Feed Name: TRU Security by Acronis

Threat Score
85/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

...
...

Acronis Threat Research Unit (TRU) reports an active espionage campaign—tracked to APT36-like activity—targeting Afghan telecoms and South Asian critical infrastructure using multiple custom implants (PATCHCORD, SHEETCORD, HACKERAI). The campaign delivers malicious Inno Setup installers and lures impersonating telecom and government services, employs diverse C2 channels (HTTP C2, Google Sheets, GitHub Gists), supports in-memory shellcode execution and extensive persistence/anti-analysis features, and leverages exposed staging infrastructure containing additional tooling and exploits (including CVE-2024-6387); numerous IOCs (SHA256s, domains, IP, registry keys) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.