PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
ID: 60534145-6ed6-542c-9117-17b5401eaf90
STIX ID: report--60534145-6ed6-542c-9117-17b5401eaf90
Feed Name: TRU Security by Acronis
Acronis Threat Research Unit (TRU) reports an active espionage campaign—tracked to APT36-like activity—targeting Afghan telecoms and South Asian critical infrastructure using multiple custom implants (PATCHCORD, SHEETCORD, HACKERAI). The campaign delivers malicious Inno Setup installers and lures impersonating telecom and government services, employs diverse C2 channels (HTTP C2, Google Sheets, GitHub Gists), supports in-memory shellcode execution and extensive persistence/anti-analysis features, and leverages exposed staging infrastructure containing additional tooling and exploits (including CVE-2024-6387); numerous IOCs (SHA256s, domains, IP, registry keys) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
