Security1 distinct publisher3 min readUpdated
Acronis says Pakistan's Transparent Tribe is running new Patchcord and Sheetcord implants against Afghan government and telecom targets, with no confirmed compromises in India.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Researchers at Acronis say Transparent Tribe, the Pakistani espionage group also tracked as APT36, has refreshed its toolset with two previously undocumented backdoors, Patchcord and Sheetcord, and used them to compromise government, telecom and incidental targets in Afghanistan [1][2][3]. The same campaign has been aimed at Indian government agencies, and according to Acronis no successful compromise there has been confirmed [4][5].
That asymmetry is the story. The campaign dates to at least last December, ramped up in May and remains ongoing [6]. Its lures impersonated network and logistics tools used by a large Afghan telecommunications company, a fuel conservation tool for India's energy sector, and an Indian government employee benefits resource, while command-and-control domains impersonated major Indian government organisations and Afghan telecoms [7][8]. In India the target list was ambitious: the Ministries of Defence and Foreign Affairs, the National Informatics Centre under the Ministry of Electronics and Information Technology, and the Indian Air Force [9]. None of it appears to have landed [5].
In Afghanistan it landed repeatedly. Dark Reading reports it confirmed an infection at an Afghan subsidiary of an international company and at an IT officer in the Khost branch of state-owned Afghan Telecom [10]. Acronis senior threat researcher Subhajeet Singha says the operators have been stealing data from that officer's desktop and reading his WhatsApp and private files, then using the material to build decoy Excel files to phish further employees and move laterally through the company [11]. Afghan victims also included a small business and an unidentified individual, which is not what a disciplined high-value targeting programme looks like [12].
The implant itself does not explain the difference. Patchcord is a C++ backdoor that fingerprints hosts, enumerates processes and, most importantly, executes arbitrary code in memory; a variant seen in March added checks for virtual machine and sandbox environments [13][14]. Set against that, its persistence mechanism is browser shortcut hijacking: rewriting the desktop shortcut so the malware runs first and the browser second, invisibly to the user [15]. Dark Reading characterises that technique as old and largely detectable [16]. So the toolset is mixed - careful about analysis, careless about persistence - and it is the same mixed toolset in both countries [17].
What varied was the defence. Nothing in the reporting suggests APT36 brought different tradecraft to Delhi than to Kabul; the delta is that Indian agencies were prepared for it and Taliban-run institutions were not [18]. Dark Reading frames the operation as a nation-state actor picking on immature organisations while failing against better-prepared government agencies [18]. A shortcut-hijacking persistence trick that any competent endpoint product flags is survivable only where nobody is looking.
Two caveats worth holding. First, "no confirmed compromise" in India is an absence of evidence from one vendor's visibility, not proof of a clean sheet [5]. Second, the Afghan telecom foothold is described as an active staging point for internal phishing, so the blast radius there is still expanding [11].
Watch whether Acronis or Indian CERT bodies later confirm any Indian intrusion from this cluster, and whether Patchcord's persistence gets rebuilt into something quieter. If APT36 fixes the shortcut hijacking while keeping the in-memory execution, the current detection advantage narrows fast [13][15].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
No successful compromises in India have yet been confirmed; no evidence suggests the attacks on Indian government agencies were successful.
Dark Reading frames the operation as a nation-state actor picking on immature organisations run by the Taliban while failing against more prepared government agencies in India, making target-side defensive maturity the variable that differed.
Patchcord is a newly documented C++ implant supporting host fingerprinting and process enumeration, and is designed to run arbitrary code in memory.
A variant of Patchcord first seen in March implemented a variety of checks for detecting whether it is running in a virtual machine or sandbox environment.
Transparent Tribe, also known as APT36, is a Pakistani threat actor and possibly Pakistan's most active advanced persistent threat group; researchers believe it works for the Pakistani state.
Researchers from Acronis observed Transparent Tribe this year using a sharpened toolset including fresh backdoors called Patchcord and Sheetcord.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-vendor research with limited independent verification
The technical substance rests entirely on one research source, Acronis, via one publisher, with a named researcher quoted on the record and the publisher independently confirming two specific Afghan infections — which is better than pure vendor-blog restatement. Against that: no indicators of compromise, hashes, domains or detection rules appear in the supplied text, no victim organization, Indian agency or Pakistani authority is given a response, no second vendor or CERT corroborates attribution, and the supplied body is truncated mid-sentence on the HackerAI framework. The negative finding in India is an absence-of-evidence statement from a single telemetry vantage point.
Confirmed but narrow real-world impact
Real-world effect is demonstrated rather than hypothetical: an ongoing campaign since at least December that escalated in May, two confirmed Afghan compromises including active exfiltration from a state telecom employee, and iterative implant development. But the confirmed footprint is small and geographically narrow, target lists are described qualitatively without counts, and the higher-value Indian target set shows no confirmed success at all, which caps how widely the campaign has actually landed.
Roughly aligned, with mild novelty framing
The framing is close to the evidence. The headline and lede language of 'novel malware' and a 'refreshed'/'sharpened-up' toolset runs slightly ahead of a build whose signature persistence trick is explicitly described in the same article as old and easily caught by common endpoint products, and the confirmed victim count is two. Offsetting that, the source volunteers the central limitation up front — no confirmed compromises in India — and quotes its researcher undercutting the sophistication narrative, so the overstatement is marginal rather than structural.
Vendor-named malware, single commercial research source
The entire technical narrative originates with Acronis, a commercial security vendor, and centers on newly named malware families it discovered — naming rights and campaign attribution are standard marketing assets for such vendors, and the closing section pivots to how endpoint products detect the technique. The publisher partly offsets this by confirming victims independently and by quoting the researcher downgrading the actor's sophistication rather than inflating it. No sponsorship, paid placement or vendor-publisher commercial relationship is disclosed in the supplied material, so this reflects structural incentive rather than an established conflict.
Moderate — specific and internally consistent, but unreplicated
Confidence is moderate. The account is specific, internally consistent, on-the-record and includes publisher-verified victims, and its own framing acknowledges the main uncertainty rather than papering over it. But it is a one-publisher, one-vendor cluster with no IOCs, no target-side comment, no independent corroboration of attribution, and a headline negative finding that is an absence of observation. The derived conclusion that identical capability met different defensive maturity is plausible but inferential, since no per-victim tooling breakdown is provided.
security
Defender's own signed driver becomes the bypass: BTR.sys and the week's trusted-component defects1 distinct publisher
security
Rogue 'Delta WiFi Fast' access point shows evil twins now land where nobody owns the network1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026