news.mlab.sh
Back to the feed
threat-intel

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

High
Image: The Hacker News
Summary

A Pakistan-aligned threat actor, APT36 (Transparent Tribe), is targeting Afghan telecom providers and critical infrastructure in South Asia with a new backdoor campaign called PATCHCORD. The campaign utilizes sector-specific lures, including fake VPN installers and hijacked domains impersonating Afghan Telecom and India's National Informatics Center (NIC), and leverages Google Sheets and GitHub Gists for command and control. A second backdoor, SHEETCORD, is also being deployed, utilizing a similar C2 approach and incorporating elements from SHEETCREEP.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.