securityaffairs.com 8/16/2026, 8:40:33 AM · external

APT36 uses fake VPN installers to deploy PATCHCORD backdoor

APT36 uses fake VPN installers to deploy PATCHCORD backdoor
CyberSIXT Evidence Panel
Primary Source acronis.com
Threat Actor

ACRONIS has uncovered a sophisticated espionage campaign attributed to APT36, involving a backdoor known as PATCHCORD that targets Afghan telecom and South Asian critical infrastructure. This malware is spread through fake VPN installers that closely mimic legitimate software. Additionally, the campaign includes SHEETCORD, a more advanced implant that utilizes Google Sheets for command and control. This technique allows attackers to disguise malicious activity within normal corporate traffic.

PATCHCORD employs unique persistence methods by hijacking browser shortcuts to run malware secretly whenever users open their browsers. It supports remote command execution and can manipulate its operation through in-memory shellcode, providing a stealthy operation.

The exposed infrastructure revealed the operator's toolkit, including command-and-control frameworks and remote access trojans, shedding light on the group's evolving tactics. The campaign indicates a growing sophistication in threat actor operations, using generative AI tools for coding, and highlights the need for robust cyber defenses for organizations operating in affected regions.

View Primary Source Via securityaffairs.com

Article by CyberSIXT