securityonline.info 8/19/2026, 10:21:02 AM · external

APT36 Uses PATCHCORD Malware Against Afghan Telecom, Indian Govt

APT36 Uses PATCHCORD Malware Against Afghan Telecom, Indian Govt
Developing story malware 2 articles tracked
APT36 deploys PATCHCORD backdoor via fake VPN installers
CyberSIXT Evidence Panel
Primary Source acronis.com
Threat Actor

THE report highlights the detection of four active exploits today, including vulnerabilities in Microsoft, Broadcom, and Apple technologies. A malicious campaign, linked to the APT36 group (Transparent Tribe), targets Afghan telecom firms and Indian government sectors through a malware cluster known as PATCHCORD which disguises itself in fake software installers. The malware executes various manipulative functions such as hijacking browser shortcuts and manipulating command and control channels via Google Sheets.

Acronis Threat Research Unit indicates that the campaign is ongoing, urging vigilance from South Asian entities against similar phishing attempts.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline