Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD.

According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.

An analysis of the threat actor's infrastructure has also led to the discovery of another Go-based backdoor dubbed SHEETCORD that uses Google Sheets for command-and-control (C2) communications. The malware has been found to be delivered via a domain impersonating India's National Informatics Center (NIC).

"The campaign's infrastructure centers on a single C2 server with multiple associated domains, including domains impersonating Afghan telecom operators and a hijacked legitimate healthcare domain," researchers Darrel Virtusio, Santiago Pontiroli, and Subhajeet Singha said in a report shared with The Hacker News.

The activity is assessed to be the work of a Pakistan-aligned threat actor known as APT36 (aka Transparent Tribe) with moderate confidence, citing overlaps in targeting patterns, malware similarities, shared infrastructure, and operational tradecraft.