PATCHCORD: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure

    Date: 08/14/2026

    Severity: High

    Summary

    The APT36 (Transparent Tribe)-linked PATCHCORD campaign is an evolving cyber espionage operation targeting telecommunications, government, defense, and critical infrastructure organizations across South Asia. The threat actor deployed PATCHCORD, SHEETCORD, and HACKERAI C2 Agent, transitioning from a custom C/C++ backdoor to Go-based implants that abuse Google Sheets and GitHub Gists for covert command-and-control. The campaign remains active, highlighting ongoing phishing operations and the continued expansion of its cloud-based C2 infrastructure. 

    Indicators of Compromise (IOC) List

    Domain/URLs

    appstoore.solutions

    www.appstoore.solutions

    afghantelecom.site

    afghanistanupdates.site

    www.afghanistanupdates.site

    caprispine.health

    www.caprispine.health

    servicesindia.services

    www.servicesindia.services

    zala-aer.info

    www.zala-aer.info

    nicservice.org

    www.nicservice.org

    nic-support.site

    appstoore.duckdns.org

    defence.cdga.sit

    IP Address

    46.30.188.13

    Hash

    cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6

    1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94

    ea0934472121848b80455581d289ce4480b1e5cc05678c1b90ecfc465b5ec350

    5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a

    378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668

    b56fab5a6834c51d85787e7c1177720dfba5a5823763f3fcf432196cd2a1bdf3

    2323b55ea743c813e48689318e8ed54ae838cf9e8a2adbfc2488ea8a36dd0126

    2eddfebb3f7419af27493a6a3bb601372cf6c494da8df62640cce7f830b4a73b

    d46ee94d6a27ff9f02cff6fb57780acac2833ce48c95e63042a6274e24a040bb

    50fc220347f9e281037e831c3755dc70a8ba7f663025aea35b301226918b016b

    0f4073d3c866bc3daf55b25f71250b96ec120db94a4f9cc8fe85b7c9f9d346b3

    959bbb09cd86ce3930406bf1cf32776ca477dfefe3fd63e90bf0017fccd90587

    74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "afghantelecom.site" or url like "afghantelecom.site" or siteurl like "afghantelecom.site" or domainname like "caprispine.health" or url like "caprispine.health" or siteurl like "caprispine.health" or domainname like "zala-aer.info" or url like "zala-aer.info" or siteurl like "zala-aer.info" or domainname like "www.zala-aer.info" or url like "www.zala-aer.info" or siteurl like "www.zala-aer.info" or domainname like "nicservice.org" or url like "nicservice.org" or siteurl like "nicservice.org" or domainname like "appstoore.duckdns.org" or url like "appstoore.duckdns.org" or siteurl like "appstoore.duckdns.org" or domainname like "www.afghanistanupdates.site" or url like "www.afghanistanupdates.site" or siteurl like "www.afghanistanupdates.site" or domainname like "defence.cdga.site" or url like "defence.cdga.site" or siteurl like "defence.cdga.site" or domainname like "www.caprispine.health" or url like "www.caprispine.health" or siteurl like "www.caprispine.health" or domainname like "afghanistanupdates.site" or url like "afghanistanupdates.site" or siteurl like "afghanistanupdates.site" or domainname like "www.nicservice.org" or url like "www.nicservice.org" or siteurl like "www.nicservice.org" or domainname like "nic-support.site" or url like "nic-support.site" or siteurl like "nic-support.site"

    Detection Query 2 :

    dstipaddress IN ("46.30.188.13") or srcipaddress IN ("46.30.188.13")

    Detection Query 3 :

    sha256hash IN ("d46ee94d6a27ff9f02cff6fb57780acac2833ce48c95e63042a6274e24a040bb","74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2","5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a","b56fab5a6834c51d85787e7c1177720dfba5a5823763f3fcf432196cd2a1bdf3","ea0934472121848b80455581d289ce4480b1e5cc05678c1b90ecfc465b5ec350","1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94","0f4073d3c866bc3daf55b25f71250b96ec120db94a4f9cc8fe85b7c9f9d346b3","50fc220347f9e281037e831c3755dc70a8ba7f663025aea35b301226918b016b","378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668","2eddfebb3f7419af27493a6a3bb601372cf6c494da8df62640cce7f830b4a73b","2323b55ea743c813e48689318e8ed54ae838cf9e8a2adbfc2488ea8a36dd0126","cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6","959bbb09cd86ce3930406bf1cf32776ca477dfefe3fd63e90bf0017fccd90587")

    Reference: 

    https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/          


    Tags

    Transparent TribeAfghanistanMalwareThreat ActorAPT36Cyber EspionageGovernment Services and FacilitiesDefense Industrial BaseCritical InfrastructureCommunicationsSouth AsiaBackdoorGitHubPhishingCloud Infrastructure

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags