APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
ID: 95fad03f-2d16-5e2a-a7c8-b2d11c188f2e
STIX ID: report--95fad03f-2d16-5e2a-a7c8-b2d11c188f2e
Feed Name: Security Affairs
Threat Score
**Executive summary:** Acronis Threat Research Unit uncovered an ongoing espionage campaign—tracked as PATCHCORD—that uses sector-specific lures (fake VPN installers and management tools) to deploy a Windows backdoor which persists by hijacking browser shortcuts; follow-on tooling (SHEETCORD, HACKERAI) abuses Google Sheets and GitHub Gists for C2, and an exposed staging server revealed the operator's toolkit and links to APT36 with moderate confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
