LIVE · cybersecurity feed
Live wire
patch

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD, […]

zeroday.news ·

A newly discovered espionage campaign, dubbed PATCHCORD, has been observed targeting Afghan telecommunications providers and critical infrastructure organizations in South Asia. Security researchers at Acronis identified a custom C/C++ backdoor, PATCHCORD, being delivered through highly specific lures, including fake VPN installers designed to impersonate legitimate tools from Afghan Telecom (AFTEL) and other telecom management utilities.

The attackers demonstrated a sophisticated understanding of their targets, with one fake installer matching the company name, product fields, and even the support portal URL of Afghan Telecom. When executed, these installers quietly deploy the 64-bit Windows implant while simultaneously opening a genuine browser session in the background, making the infection appear seamless to the user.

PATCHCORD establishes persistence by hijacking browser shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox. It first checks for elevated privileges, then backs up the original shortcut files and rewrites them to launch the malware before the legitimate browser. This ensures that every time a user clicks their browser icon, the malware runs invisibly in the background.

Once installed, PATCHCORD communicates with its command and control (C2) server and supports five primary functions: adjusting its check-in frequency, listing running processes, executing shellcode entirely in memory, running arbitrary commands via a hidden shell, and remotely controlling its browser-hijacking persistence mechanism. The in-memory shellcode execution is particularly notable as it minimizes forensic evidence on disk.

Further investigation into the campaign's infrastructure led researchers to a more advanced, Go-based implant named SHEETCORD. This malware, distributed through a domain impersonating India's National Informatics Centre (NIC), builds upon PATCHCORD's capabilities and abuses the Google Sheets API for C2 communications. SHEETCORD creates a dedicated spreadsheet tab for each victim to send and receive instructions, a technique that allows malicious traffic to blend in with normal corporate network activity. Its command execution capability uses `powershell -Command` with script block wrapping, an evolution from PATCHCORD's `cmd.exe /c` approach.

Researchers also uncovered a third malware family, the HACKERAI C2 Agent, which utilizes GitHub Gists for C2. This agent exhibits characteristics consistent with AI-assisted code generation, including debug messages, AI-style code comments, and a redundant double-XOR routine using the same key. This suggests that the threat actors are employing large language models (LLMs) as ordinary coding shortcuts.

A significant breakthrough in the investigation was the discovery of an unsecured staging server left exposed by the operator. This server contained the full toolkit used by the threat actor, including SuperShell, a Chinese-language C2 framework, multiple remote access trojan frameworks, credential-harvesting tools, exploit code for a known OpenSSH vulnerability, and files formatted like iOS call history databases, indicating potential mobile device data exfiltration.

While Acronis has not definitively attributed the campaign, the sophistication of the tooling and targeting aligns with known tactics of advanced persistent threat (APT) groups. The specific targeting of Afghan telecom and South Asian critical infrastructure suggests a state-sponsored espionage motive.

patchnation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and