
APT36, the Pakistan‑linked espionage group also known as Transparent Tribe, has been observed distributing a new backdoor called PATCHCORD through counterfeit VPN installers aimed at Afghan telecom providers and Indian government entities. The campaign, uncovered by Acronis Threat Research Unit, is ongoing and focuses on stealing credentials and maintaining persistent access to critical networks.
PATCHCORD arrives as a fake VPN setup program that, once executed, hijacks the target’s browser shortcuts so the malware launches each time the user opens Chrome, Edge or Firefox. It runs payloads from memory, using in-memory shellcode to avoid writing files to disk, and can accept arbitrary commands from its operators. Command‑and‑control is handled through a separate component dubbed SHEETCORD, which stores instructions and exfiltrates data in innocuous‑looking Google Sheets, blending with normal cloud traffic.
Acronis notes that the PATCHCORD activity coincides with the recent exploitation of several n-day flaws in Microsoft, Broadcom and Apple products, although no CVE identifiers have been directly tied to the backdoor itself. The threat intelligence feed observed four active exploits today, highlighting how attackers chain old vulnerabilities with fresh social engineering to maximise impact.
The activity is tracked under Operation C‑Major and reflects APT36’s continued focus on South Asian telecoms and governmental sectors for intelligence gathering. By masquerading as legitimate VPN tools, the group exploits the heightened demand for secure remote access in the region, a tactic that has proven effective in previous campaigns.
Organisations should verify the authenticity of any VPN installer before execution, checking digital signatures and downloading only from vendor-approved sites. Monitoring for unexpected changes to browser shortcut files and for outbound connections to Google Sheets endpoints can reveal early signs of PATCHCORD or SHEETCORD activity. Applying the latest patches for the disclosed Microsoft, Broadcom and Apple vulnerabilities, tightening application‑control policies and conducting phishing‑awareness training further reduce the risk of successful infection.
Acronis TRU recommends maintaining updated threat‑intelligence feeds and reviewing logs for the specific indicators associated with this cluster, such as particular registry keys and user-agent strings linked to the fake installers. Staying vigilant against social engineering lures that promise VPN connectivity remains essential for defending South Asian critical infrastructure against this evolving threat.