TelcoNews Ireland - Telecommunications news for ICT decision-makers
Ireland
APT36-linked malware cluster targets South Asia telecoms

APT36-linked malware cluster targets South Asia telecoms

Mon, 17th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Acronis has identified a malware cluster targeting telecommunications providers and critical infrastructure organisations in Afghanistan and South Asia. It linked the activity with moderate confidence to APT36 or a closely related Pakistan-linked threat actor.

The cluster includes three previously undocumented malware families: PATCHCORD, SHEETCORD and HACKERAI C2 Agent. The operation has focused on telecom, government, defence and energy-related targets, using lures that impersonate Afghan Telecom, Afghanistan's Ministry of Communications and Information Technology, India's National Informatics Centre and India's National Hydroelectric Power Corporation.

At the centre of the investigation is PATCHCORD, a custom C and C++ backdoor delivered through malicious Inno Setup installers. It was designed to appear legitimate, including as a fake Afghan telecom management tool and an installer themed around an Indian energy client.

Once installed, PATCHCORD establishes persistence by hijacking browser shortcuts, allowing it to run in the background when a user opens a browser. It can fingerprint an infected machine, register with a command-and-control server, run remote shell commands, enumerate processes and execute shellcode in memory without writing it to disk.

The group's infrastructure used a hardcoded command-and-control domain and remained active during the investigation. An exposed staging server gave researchers an unusually detailed view of the operator's methods, including phishing lures, malware samples, exploit tools, credential-harvesting software and signs of possible stolen data.

Cloud services

Two other malware families were found on the same infrastructure. SHEETCORD, a Go-based implant, used Google Sheets for command-and-control communications, while HACKERAI C2 Agent used GitHub Gists.

The use of trusted cloud platforms is notable because it can help malicious traffic blend into normal business activity. According to the technical analysis, SHEETCORD creates per-victim spreadsheet tabs for two-way communications, while HACKERAI C2 Agent uploads and downloads tasking through GitHub Gists.

SHEETCORD was distributed through a domain impersonating India's National Informatics Centre and delivered through an installer presented as a Ministry of Defence Employee Breach Update. It shares some of PATCHCORD's functions, including remote command execution and browser shortcut hijacking, but adds a startup folder script and a registry run key for persistence.

Unlike PATCHCORD, which targets three browsers, SHEETCORD supports six, including Brave, Opera and Vivaldi. Its code also uses VBScript to rewrite shortcuts on the victim's machine.

HACKERAI C2 Agent appears to predate the other two malware families and was tied to a domain impersonating India's Controller General of Defence Accounts. The implant contains code comments, debugging messages and implementation patterns consistent with AI-assisted development.

Targeting patterns

The campaign appears to have broadened over time. Researchers traced domains impersonating Afghan telecom providers, Indian government agencies and a Delhi healthcare provider, all pointing to the same server over several months.

One strand focused on Afghan telecom providers, valuable espionage targets because they can provide access to communications infrastructure, subscriber information and official communications. Another targeted Indian defence personnel through defence-themed lures, while a separate campaign used an energy-sector lure tied to NHPC.

The exposed server also contained exploit tooling for CVE-2024-6387, known as regreSSHion, and CVE-2021-4034, known as PwnKit, alongside brute-force artefacts and open-source frameworks. This suggests the operator may be combining phishing with attempts to gain access through vulnerable internet-facing systems.

Researchers also found SuperShell, Metasploit, GateSentinel and a browser credential-harvesting tool on the same server. Some of those tools have been associated with earlier APT36 activity, adding weight to the attribution, although Acronis stopped short of making a definitive link.

Several indicators point to overlap with APT36, also known as Transparent Tribe, including the sustained focus on Afghan and Indian targets, the presence of tooling seen in earlier operations and the use of Google Sheets in a manner resembling previously documented malware linked to the group.

"The discovery of PATCHCORD, SHEETCORD, and HACKERAI C2 Agent highlights the operator's continued evolution, from a custom C/C++ backdoor to Go-based implants that abuse legitimate cloud services, including Google Sheets and GitHub Gists, for command-and-control," said Subhajeet Singha, Darrel Virtusio and Santiago Pontiroli, authors at Acronis.