Malware Cluster Hits Afghan Telecom

Perth, Aug 20: Security researchers have uncovered a new espionage campaign targeting Afghan telecom providers and government, defence and infrastructure organisations across South Asia, according to research published by Acronis’s Threat Research Unit (TRU), authored by Subhajeet Singha, Darrel Virtusio and Santiago Pontiroli.
The team identified three previously undocumented malware families used in the campaign PATCHCORD, SHEETCORD, and an implant dubbed HACKERAI C2 Agent.
Telecom operators were singled out as high-value targets, given their access to communications infrastructure and both government and subscriber data.
PATCHCORD, the primary backdoor, is disguised inside fake installers impersonating Afghan Telecom, Afghanistan’s Ministry of Communications and Information Technology, and India’s National Hydroelectric Power Corporation.
Once installed, it grants remote access to a victim’s system, hijacks browser shortcuts to maintain persistence, and can run malicious code entirely in a device’s memory, a technique that leaves few traces for investigators to find later.
Following the infrastructure trail, researchers found a related campaign using SHEETCORD, a variant that abuses Google Sheets to send and receive commands, aimed at personnel within India’s Ministry of Defense. A third tool, HACKERAI C2 Agent, instead relies on GitHub Gists for the same purpose, and researchers noted signs the malware’s code may have been partly written with AI coding assistance.
Investigators also found an exposed staging server that revealed a broader operational toolkit including phishing materials, hacking frameworks such as SuperShell and GateSentinel, and tools built to exploit a known SSH vulnerability (CVE-2024-6387), along with what appears to be data taken from previous victims.
Based on targeting patterns, overlapping tools and shared infrastructure, TRU said it assesses with moderate confidence that the campaign is linked to APT36 (also known as Transparent Tribe), a threat group believed to be based in Pakistan and long associated with espionage against government, military and diplomatic targets in the region.
Researchers noted the campaign marks a shift for the group, expanding its focus toward Afghan telecom providers while adopting new malware and cloud-based methods for controlling infected systems.
At the time of publication, TRU said the campaign’s infrastructure remained active, and the firm is continuing to monitor the activity.

Leave a Reply

Discover more from DailyStraits.com

Subscribe now to keep reading and get access to the full archive.

Continue reading