Listen to this Post
A New and More Dangerous Chapter in Regional Cyber Espionage
Cyber espionage rarely announces itself with dramatic warnings. More often, it arrives disguised as something employees already trust: a software update, a service utility, a government document, or an ordinary browser shortcut.
That is what makes the latest campaign attributed with moderate confidence to APT36, also known as Transparent Tribe, particularly concerning. Researchers have uncovered three previously undocumented malware families—PATCHCORD, SHEETCORD, and HACKERAI C2 Agent—in a campaign targeting organizations across Afghanistan and India.
The activity focuses on telecom, government, defense, and energy organizations, sectors that collectively hold some of the most strategically valuable information in a country. Telecommunications infrastructure alone can expose subscriber information, internal communications, network architecture, and potentially sensitive relationships between government institutions and private companies.
The campaign also reflects a broader evolution in the threat landscape. APT groups are no longer limiting themselves to traditional military and government espionage. Telecommunications providers, energy companies, technology vendors, and other organizations increasingly sit on information that can be just as valuable as classified documents.
The Core Story: Trust Is Being Weaponized
At the center of the campaign is a deceptively simple idea: make malicious software look familiar.
Researchers discovered a suspicious ZIP archive named Telecom_TMS on VirusTotal in June 2026. Inside was an executable called TMS_AfghanTelecom.exe, presented as though it were a legitimate management utility associated with Afghan Telecom.
The installer reportedly incorporated Afghan Telecom branding into its metadata and even referenced the legitimate Afghan Telecom service-request portal in its publisher information.
That is not a technical vulnerability in itself. It is psychological engineering.
An employee who sees familiar branding, a familiar organization name, and what appears to be a legitimate software utility may have little reason to suspect that the executable is actually the first stage of an intrusion.
Once executed, however, the installer drops PATCHCORD, a custom 64-bit Windows backdoor written in C/C++.
PATCHCORD: A Backdoor Designed to Stay Out of Sight
PATCHCORD demonstrates several characteristics that make it particularly dangerous in a corporate environment.
The malware hides its console window, collects information about the compromised machine, establishes communication with its command-and-control infrastructure, and waits for instructions from its operators.
That basic functionality is common among modern remote-access implants. What makes PATCHCORD more interesting is how it attempts to blend into the victim’s normal computing experience.
Browser Shortcuts Become the Persistence Mechanism
One of the
PATCHCORD reportedly modifies shortcuts associated with Microsoft Edge, Google Chrome, and Mozilla Firefox so that the malicious component executes before the legitimate browser launches.
From the
The browser opens.
The expected interface appears.
Websites continue loading.
Nothing necessarily crashes.
Meanwhile, malicious code can be running quietly in the background.
This is an important reminder that persistence does not always require an obvious startup entry or a suspicious Windows service. Attackers can abuse familiar operating-system mechanisms in ways that remain almost invisible to ordinary users.
Command Execution and Memory-Based Payloads
PATCHCORD can enumerate running processes and execute commands through cmd.exe. It can also modify its beacon interval and execute shellcode directly in memory.
The memory-execution capability is especially relevant to defenders because payloads that avoid being written to disk can complicate traditional forensic collection.
File-based detection remains valuable, but it cannot be the only layer of defense.
An organization that monitors only newly created executable files may miss important stages of an intrusion occurring inside already-running processes.
The Command-and-Control Infrastructure
According to the supplied research, PATCHCORD communicated with appstoore[.]solutions over TCP port 8080.
Infrastructure analysis reportedly associated the campaign with 46.30.188[.]13, where multiple domains appeared to impersonate Afghan telecom services, Indian government entities, and other organizations.
Another domain, nic-support[.]site, was reportedly used to imitate India’s National Informatics Centre.
The use of infrastructure that resembles government or telecom organizations is significant because domain names can become part of the attack itself. A convincing domain can reinforce a phishing story, provide a believable download location, or help an operator appear legitimate during an intrusion.
SHEETCORD Expands the Attack Surface
The campaign does not stop with PATCHCORD.
Researchers also identified SHEETCORD, a Go-based malware implant delivered through a fake Ministry of Defense update installer.
SHEETCORD reportedly shares several capabilities with PATCHCORD, including remote command execution and browser shortcut manipulation.
But it goes further in its persistence strategy.
The malware reportedly uses a VBScript placed in the Windows Startup folder, providing another route to execute malicious code whenever a user logs into the system.
According to the supplied research, SHEETCORD also supports a wider browser ecosystem, including Chrome, Firefox, Edge, Brave, Opera, and Vivaldi.
Why Browser Hijacking Is More Important Than It Looks
Browser shortcuts are easy to underestimate because they are ordinary files that users interact with every day.
That makes them attractive to attackers.
Traditional security teams often concentrate on registry run keys, scheduled tasks, services, startup folders, and obvious executable persistence. Shortcut manipulation adds another location to the defender’s checklist.
It also illustrates a broader principle: legitimate operating-system functionality can become malicious infrastructure without being inherently malicious itself.
HACKERAI C2 Agent Raises Another Question
The third previously undocumented component identified in the campaign is referred to as the HACKERAI C2 Agent.
Its inclusion is particularly interesting because the name suggests an association with AI-assisted command-and-control activity. However, the existence of an AI-related name should not automatically be interpreted as proof that the operators are using a sophisticated autonomous AI system.
Names assigned to malware can originate from researchers, observed artifacts, internal naming conventions, or characteristics discovered during reverse engineering.
The more important question is what the component actually does and how it fits into the broader intrusion chain.
APT36 Attribution Remains a Confidence Assessment
Researchers assess the connection to APT36 with moderate confidence, rather than treating attribution as absolute fact.
That distinction matters.
Attribution in cybersecurity is rarely established by one file or one domain. Analysts typically build a case using multiple overlapping signals: targeting patterns, infrastructure reuse, coding similarities, operational behavior, malware capabilities, and relationships between different campaign artifacts.
The reported similarities between the newly discovered tools and previously associated APT36 activity therefore strengthen the assessment, but they do not eliminate uncertainty.
A responsible threat-intelligence report should preserve that uncertainty.
Why Afghanistan and India Matter to the Campaign
The targeting geography provides another important clue.
Afghanistan and India have previously appeared in cyber-espionage campaigns involving government, military, diplomatic, telecommunications, and strategic organizations.
The reported targeting of these countries by the current campaign therefore fits a broader regional intelligence-gathering context.
But the targeting of telecom companies deserves particular attention.
Telecommunications organizations are not merely businesses that provide phone and internet services. Their infrastructure can provide visibility into enormous quantities of communications metadata, customer information, network relationships, and operational systems.
Telecom Companies Are Strategic Intelligence Targets
Compromising a telecom provider could potentially give an attacker access to information that helps map an entire ecosystem.
Who communicates with whom?
Which government systems connect to which networks?
Which organizations share infrastructure?
Which individuals are associated with particular departments?
Which systems are most important?
Even without intercepting the content of communications, metadata and infrastructure information can be extraordinarily valuable for intelligence operations.
This makes telecom providers a natural target for actors interested in long-term strategic collection.
The Campaign Shows an Expansion Beyond Traditional Espionage
The targeting pattern described in the research suggests that APT36-linked operations are moving beyond the classic image of an attacker pursuing only ministries or military organizations.
Energy companies can reveal information about national infrastructure.
Telecom providers can reveal communications and network relationships.
Technology companies can provide access to software ecosystems and credentials.
Government contractors can become gateways into larger networks.
The modern espionage battlefield is therefore increasingly distributed.
Social Engineering Is Still the Opening Move
Despite the sophisticated persistence techniques, the campaign reportedly begins with a remarkably old-fashioned strategy: convince somebody to run a file.
This remains one of the strongest lessons from the incident.
Attackers do not necessarily need to defeat every security control if they can persuade a trusted employee to bypass the first layer of protection.
A malicious installer with convincing government or telecom branding can exploit assumptions that antivirus software, email filtering, and ordinary users may all make.
The Danger of Familiar Branding
Brand impersonation is powerful because people naturally use visual and contextual shortcuts to determine whether something is trustworthy.
A familiar logo feels safe.
A familiar company name feels safe.
A legitimate publisher URL looks reassuring.
A document named after a routine internal process feels harmless.
But none of those characteristics prove that an executable is legitimate.
The file itself must be independently validated.
Deep Analysis: How Defenders Should Investigate
The most effective response to this campaign is not to hunt for one domain or one malware filename. Defenders should search for the behavioral patterns described in the campaign.
Start with endpoint telemetry.
Look for unusual modifications to browser shortcut files, particularly when the shortcut’s target contains unexpected executables, scripts, command interpreters, or arguments.
On Windows systems, defenders can examine shortcut targets using PowerShell:
$paths = @(
$env:PUBLIC\Desktop,
$env:USERPROFILE\Desktop,
$env:APPDATA\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar
)
Get-ChildItem $paths -Filter .lnk -Recurse -ErrorAction SilentlyContinue |
ForEach-Object {
$shell = New-Object -ComObject WScript.Shell
$shortcut = $shell.CreateShortcut($<em>.FullName)
[PSCustomObject]@{
Path = $</em>.FullName
Target = $shortcut.TargetPath
Args = $shortcut.Arguments
}
}
Hunt for Suspicious Command Execution
Because PATCHCORD reportedly uses cmd.exe, security teams should investigate unusual command-shell activity originating from browser-related processes or unexpected user applications.
A simple Windows event-log search can help identify command-line activity:
Get-WinEvent -FilterHashtable @{
LogName='Security'
Id=4688
} -ErrorAction SilentlyContinue |
Where-Object {
$_.Message -match 'cmd.exe|powershell.exe|wscript.exe|cscript.exe'
}
This should be treated as a hunting aid rather than a complete detection rule.
Investigate Startup-Folder Persistence
Because SHEETCORD reportedly uses the Windows Startup folder, defenders should inspect both user and system startup locations.
$startupPaths = @(
$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup,
$env:ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
)
foreach ($path in $startupPaths) {
if (Test-Path $path) {
Get-ChildItem $path -Force |
Select-Object FullName, Length, LastWriteTime
}
}
Unexpected .vbs, .js, .cmd, .bat, .exe, or shortcut files deserve investigation, particularly when their creation timestamps align with a suspicious software installation.
Search for Suspicious VBScript Execution
Organizations that do not normally rely on VBScript should pay particular attention to wscript.exe and cscript.exe.
For example:
Get-WinEvent -FilterHashtable @{
LogName='Microsoft-Windows-Sysmon/Operational'
Id=1
} -ErrorAction SilentlyContinue |
Where-Object {
$_.Message -match 'wscript.exe|cscript.exe'
}
Sysmon configuration varies between environments, so the absence of events does not prove that script execution did not occur.
Examine Network Connections
Network telemetry should be used to identify unexpected outbound connections from workstations.
The reported infrastructure includes a C2 domain and IP address, but defenders should not depend exclusively on static indicators because attackers can rotate domains and servers.
A basic Windows connection check can be performed with:
Get-NetTCPConnection -State Established | Sort-Object RemotePort | Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,OwningProcess
For production detection, endpoint telemetry, DNS logs, proxy logs, firewall records, and SIEM correlation should be combined.
Search the Environment Without Resolving Malicious Domains
The reported indicators should remain defanged during ordinary documentation and ticketing.
Example:
appstoore[.]solutions
46.30.188[.]13
afghantelecom[.]site
nic-support[.]site
Security teams can search these strings across their SIEM, EDR, DNS, proxy, and firewall datasets without accidentally turning a threat-intelligence indicator into an active network destination.
A Better Detection Strategy: Behavior Over Indicators
Indicators of compromise are useful, but they expire.
Domains disappear.
Servers move.
Hashes change.
Attackers rebuild infrastructure.
The behavior of the malware is harder to replace.
Browser shortcut manipulation, unusual script execution, suspicious child processes, memory execution, and unexpected outbound connections can all remain valuable detection signals even after the original infrastructure disappears.
What Undercode Say: The Real Threat Is the Combination
The most concerning element of this campaign is not any individual malware family.
It is the combination of social engineering, legitimate branding, persistence abuse, remote command execution, memory-based execution, and infrastructure impersonation.
Each technique addresses a different part of the defender’s security architecture.
The fake installer attacks human trust.
The shortcut modification attacks endpoint persistence monitoring.
The command shell provides operational flexibility.
Memory execution complicates traditional file-based investigation.
The impersonated infrastructure makes the campaign appear legitimate.
Together, these techniques create a layered intrusion strategy.
The campaign also demonstrates why organizations should stop thinking about malware as simply “a bad executable.”
The executable is only one component.
The real attack is a chain.
That chain begins with credibility.
Then comes execution.
Then persistence.
Then command and control.
Then collection.
Then potentially lateral movement and long-term espionage.
Breaking any one of those stages can prevent the attacker from achieving the final objective.
The telecom targeting is particularly significant because communications infrastructure is an intelligence multiplier.
An attacker does not necessarily need to compromise every government department individually if compromising a strategically positioned telecom or technology provider provides useful visibility into those organizations.
This creates a dangerous concentration of risk.
The use of fake government and telecom identities also shows that attackers understand their victims.
A random malicious filename may be ignored.
A file apparently issued by a
This is why security awareness training needs to evolve beyond generic warnings about suspicious attachments.
Employees should be trained to question unexpected software installers, even when those installers appear to come from organizations they recognize.
Software authenticity should be verified through established channels.
Security teams should also monitor changes to browser shortcuts.
This is an easily overlooked persistence mechanism that deserves much more attention.
The campaign reinforces the value of EDR products capable of recording process trees, command lines, script execution, network connections, and memory-related behavior.
Without that telemetry, a stealthy implant can look like an ordinary application.
The reported use of VBScript is another reminder that legacy scripting technologies remain relevant to attackers.
Organizations should know exactly where scripting engines are required and where they can be restricted.
Application control can also reduce the probability that employees can execute arbitrary installers from temporary directories, downloads folders, or removable media.
Network segmentation is equally important.
A compromised workstation should not automatically have unrestricted access to sensitive telecom, government, or administrative systems.
Least privilege can dramatically reduce the value of an initial compromise.
DNS monitoring should also be treated as a strategic security control.
Newly registered domains, lookalike domains, suspicious country-code combinations, and infrastructure impersonating internal or government organizations can all provide early warning.
The campaign demonstrates why threat intelligence should be integrated into operational detection rather than simply stored in a report.
An IOC that never reaches the SIEM, firewall, EDR, or DNS layer provides limited defensive value.
Attribution should also be handled carefully.
APT36 is a useful analytical hypothesis, but defenders should focus on the observed behaviors regardless of which group ultimately receives credit.
If another actor copied the same techniques tomorrow, the defensive requirements would remain almost identical.
The appearance of an “AI” reference in the HACKERAI C2 Agent name should likewise be treated cautiously.
Cybersecurity has entered an era where attackers increasingly experiment with AI, but a malware label alone is not evidence of autonomous AI-driven operations.
The strongest conclusions should come from observed functionality.
Ultimately, this campaign is another warning that attackers are becoming better at hiding inside ordinary workflows.
The most effective defense is therefore not simply better antivirus.
It is layered visibility.
It is identity verification.
It is application control.
It is endpoint telemetry.
It is network monitoring.
It is rapid threat hunting.
And above all, it is the ability to recognize when normal-looking activity is behaving abnormally.
✅ The Campaign Targets High-Value Sectors
The supplied report identifies telecommunications, government, defense, and energy organizations in Afghanistan and India as primary targets.
This targeting profile is consistent with the strategic value of communications and critical infrastructure organizations, although individual campaign claims should ultimately be validated against the original research publication.
✅ PATCHCORD and SHEETCORD Are Described as Distinct Malware Families
The source material clearly distinguishes PATCHCORD, SHEETCORD, and HACKERAI C2 Agent as separate previously undocumented components.
The reported differences in implementation and persistence mechanisms support treating them as distinct malware artifacts rather than simply different versions of one executable.
⚠️ APT36 Attribution Should Remain Qualified
The
A web search conducted for this rewrite did not surface a sufficiently authoritative primary publication independently confirming the specific PATCHCORD/SHEETCORD claims, so those campaign-specific details should be regarded as reported findings rather than independently verified facts.
⚠️ The HACKERAI Name Does Not Prove AI-Driven Malware
The term “HACKERAI C2 Agent” should not automatically be interpreted as evidence that the malware autonomously uses a large language model.
A malware name can describe an artifact, research classification, or observed component without proving the underlying architecture.
Indicators of Compromise
C2 Domain
appstoore[.]solutions
C2 IP Address
46.30.188[.]13
Reported Malicious Domain
afghantelecom[.]site
Additional Reported Infrastructure
nic-support[.]site
These indicators are intentionally defanged. They should be imported into controlled threat-intelligence systems such as a SIEM, EDR, MISP, or other security-analysis platform rather than directly opened in a browser.
Defensive Priorities for Security Teams
Verify Software Through Trusted Channels
Do not rely on logos, filenames, publisher URLs, or familiar branding to establish whether an installer is legitimate.
Monitor Browser Shortcut Changes
Unexpected modifications to Chrome, Edge, Firefox, Brave, Opera, or Vivaldi shortcuts should generate investigation signals.
Monitor Script Interpreters
Track unusual use of wscript.exe, cscript.exe, PowerShell, and cmd.exe, especially when launched by unexpected parent processes.
Monitor Startup Persistence
Audit Startup folders and other persistence locations for recently created scripts, executables, and shortcuts.
Correlate Endpoint and Network Telemetry
A suspicious shortcut modification becomes much more significant when it occurs on the same machine that subsequently contacts an unusual external domain.
Restrict Unnecessary Script Execution
Where operationally possible, reduce the attack surface presented by legacy scripting engines and unnecessary execution paths.
Apply Least Privilege
Users should not have administrative privileges unless they genuinely require them.
Segment Critical Infrastructure
Telecom, energy, government, and other sensitive systems should not be directly reachable from ordinary user workstations without appropriate security controls.
Prediction
(+1) Detection Will Move Toward Behavioral Hunting
The most likely positive development is that campaigns such as this will push organizations toward stronger behavioral detection rather than relying exclusively on malware hashes and domain blocklists.
Security teams will increasingly hunt for suspicious shortcut modification, unusual script execution, abnormal process relationships, memory activity, and unexpected network behavior.
The same approach can detect future variants even when attackers replace their malware and infrastructure.
(+1) Telecom Security Will Receive Greater Attention
Telecommunications organizations are likely to receive greater scrutiny as espionage groups increasingly recognize their strategic value.
Expect stronger endpoint controls, network segmentation, identity protection, threat intelligence, and continuous monitoring around telecom environments.
(-1) Lookalike Software Attacks Will Continue Growing
Attackers have little reason to abandon fake installers and impersonation because the technique continues to exploit one of the weakest points in any security program: human trust.
As organizations become better at identifying conventional phishing, attackers will increasingly tailor fake updates and utilities to specific industries and regional organizations.
(-1) Persistence Abuse Will Become Harder to Spot
Techniques such as browser shortcut hijacking demonstrate how attackers can hide inside legitimate user workflows.
Future campaigns may increasingly manipulate ordinary configuration files, shortcuts, scripts, and application launch mechanisms rather than relying only on traditional malware persistence.
Final Verdict: The Most Dangerous Malware Is the One That Looks Normal
The PATCHCORD and SHEETCORD campaign is a reminder that sophisticated cyber espionage does not always require an exotic exploit.
Sometimes the attacker only needs a convincing filename, familiar branding, a believable download, and enough persistence to remain hidden.
What follows can be considerably more sophisticated: remote command execution, process discovery, memory-based payloads, browser manipulation, scripted persistence, and carefully constructed command-and-control infrastructure.
For defenders, the lesson is straightforward.
Do not ask only whether a file is malicious. Ask what changed, what launched it, what it launched next, where it connected, and why it behaved that way.
That shift—from detecting files to understanding behavior—is increasingly becoming the difference between discovering an intrusion early and discovering it after the attacker has already learned everything they came to find.
▶️ Related Video (80% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




