Afghan Telecoms and Indian Infrastructure Hit by New Cyber Espionage Campaign
A new cyber espionage campaign has been discovered targeting Afghan telecom providers and South Asian critical infrastructure organizations. The campaign delivers a previously undocumented backdoor called PATCHCORD, which is a compiled C/C++ implant. According to Acronis Threat Research Unit (TRU), the backdoor is delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
The analysis of the threat actor's infrastructure has also led to the discovery of another Go-based backdoor dubbed SHEETCORD that uses Google Sheets for command-and-control (C2) communications. The malware was found to be delivered via a domain impersonating India's National Informatics Center (NIC).