Skip to content

Security1 publisher3 min readPublished

Same Backdoors, Two Outcomes: APT36 Lands in Kabul, Stalls in Delhi

Acronis says Pakistan's Transparent Tribe is running new Patchcord and Sheetcord implants against Afghan government and telecom targets, with no confirmed compromises in India.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Transparent Tribe, also known as APT36, is a Pakistani threat actor and possibly Pakistan's most active advanced persistent threat group; researchers believe it works for the Pakistani state.
  • Researchers from Acronis observed Transparent Tribe this year using a sharpened toolset including fresh backdoors called Patchcord and Sheetcord.
  • Recent Transparent Tribe targets in Afghanistan included major government and telecommunications organisations, according to Acronis.
  • The group also appears to have been targeting Indian organisations.
  • No successful compromises in India have yet been confirmed; no evidence suggests the attacks on Indian government agencies were successful.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Researchers at Acronis say Transparent Tribe, the Pakistani espionage group also tracked as APT36, has refreshed its toolset with two previously undocumented backdoors, Patchcord and Sheetcord, and used them to compromise government, telecom and incidental targets in Afghanistan [1][2][3]. The same campaign has been aimed at Indian government agencies, and according to Acronis no successful compromise there has been confirmed [4][5].

That asymmetry is the story. The campaign dates to at least last December, ramped up in May and remains ongoing [6]. Its lures impersonated network and logistics tools used by a large Afghan telecommunications company, a fuel conservation tool for India's energy sector, and an Indian government employee benefits resource, while command-and-control domains impersonated major Indian government organisations and Afghan telecoms [7][8]. In India the target list was ambitious: the Ministries of Defence and Foreign Affairs, the National Informatics Centre under the Ministry of Electronics and Information Technology, and the Indian Air Force [9]. None of it appears to have landed [5].

In Afghanistan it landed repeatedly. Dark Reading reports it confirmed an infection at an Afghan subsidiary of an international company and at an IT officer in the Khost branch of state-owned Afghan Telecom [10]. Acronis senior threat researcher Subhajeet Singha says the operators have been stealing data from that officer's desktop and reading his WhatsApp and private files, then using the material to build decoy Excel files to phish further employees and move laterally through the company [11]. Afghan victims also included a small business and an unidentified individual, which is not what a disciplined high-value targeting programme looks like [12].

The implant itself does not explain the difference. Patchcord is a C++ backdoor that fingerprints hosts, enumerates processes and, most importantly, executes arbitrary code in memory; a variant seen in March added checks for virtual machine and sandbox environments [13][14]. Set against that, its persistence mechanism is browser shortcut hijacking: rewriting the desktop shortcut so the malware runs first and the browser second, invisibly to the user [15]. Dark Reading characterises that technique as old and largely detectable [16]. So the toolset is mixed - careful about analysis, careless about persistence - and it is the same mixed toolset in both countries [17].

What varied was the defence. Nothing in the reporting suggests APT36 brought different tradecraft to Delhi than to Kabul; the delta is that Indian agencies were prepared for it and Taliban-run institutions were not [18]. Dark Reading frames the operation as a nation-state actor picking on immature organisations while failing against better-prepared government agencies [18]. A shortcut-hijacking persistence trick that any competent endpoint product flags is survivable only where nobody is looking.

Two caveats worth holding. First, "no confirmed compromise" in India is an absence of evidence from one vendor's visibility, not proof of a clean sheet [5]. Second, the Afghan telecom foothold is described as an active staging point for internal phishing, so the blast radius there is still expanding [11].

Watch whether Acronis or Indian CERT bodies later confirm any Indian intrusion from this cluster, and whether Patchcord's persistence gets rebuilt into something quieter. If APT36 fixes the shortcut hijacking while keeping the in-memory execution, the current detection advantage narrows fast [13][15].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories