APT36-linked malware cluster targets South Asia telecoms

Security researchers have identified a malware cluster linked to the threat actor APT36 targeting telecommunications and critical infrastructure in South Asia. The attackers used sophisticated backdoors and cloud services like Google Sheets and GitHub to evade detection.
Why it matters
The targeting of critical infrastructure and government entities in South Asia poses significant national security and data privacy risks.
Acronis has identified a malware cluster targeting telecommunications providers and critical infrastructure organisations in Afghanistan and South Asia. It linked the activity with moderate confidence to APT36 or a closely related Pakistan-linked threat actor.
The cluster includes three previously undocumented malware families: PATCHCORD, SHEETCORD and HACKERAI C2 Agent. The operation has focused on telecom, government, defence and energy-related targets, using lures that impersonate Afghan Telecom, Afghanistan's Ministry of Communications and Information Technology, India's National Informatics Centre and India's National Hydroelectric Power Corporation.
At the centre of the investigation is PATCHCORD, a custom C and C++ backdoor delivered through malicious Inno Setup installers. It was designed to appear legitimate, including as a fake Afghan telecom management tool and an installer themed around an Indian energy client.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in