APT36 Suspected in Sophisticated Espionage Campaign Using Google Sheets C2
A sophisticated espionage campaign has been uncovered by researchers at Acronis, targeting Afghan telecom providers and South Asian critical infrastructure. The operation, dubbed PATCHCORD, uses fake VPN tools and Google Sheets command-and-control (C2) to deliver a custom backdoor.
The backdoor, compiled in C/C++, is delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom. Once installed, it hijacks browser shortcuts for Edge, Chrome, and Firefox, allowing the malware to run invisibly in the background before the browser opens.
Researchers also discovered a second implant, SHEETCORD, written in Go and delivered through a domain impersonating India's National Informatics Centre. This malware uses Google Sheets API for C2 communication, creating a dedicated spreadsheet tab for each victim to send and receive instructions.