The state-sponsored threat actor Transparent Tribe (APT 36) has deployed new malware, Patchcord and Sheetcord, to spy on high-value targets. While successful in compromising Afghan institutions, the group has failed to breach India's hardened government networks.

  • Pakistani threat actor Transparent Tribe (APT 36) has updated its toolkit with 'Patchcord' and 'Sheetcord' malware.
  • Major Afghan government and telecom organizations have been successfully compromised.
  • Targeting attempts against India's Ministry of Defense and Air Force were detected and thwarted.
  • The group utilizes 'browser shortcut hijacking' to maintain stealthy persistence.

Cybersecurity researchers have uncovered a significant escalation in activities by Transparent Tribe, also known as APT 36, a prominent Pakistani-linked nation-state threat actor. According to recent findings from Acronis, the group has refreshed its arsenal with sophisticated new tools designed for deep-seated espionage in South Asia, specifically targeting Afghanistan and India.

The campaign has seen alarming success in Afghanistan. The threat actor has successfully breached high-value targets, including an IT officer at the state-owned Afghan Telecom (AFTEL). By infecting the officer's device, the hackers gained access to private data and WhatsApp communications, which they are now leveraging to craft even more convincing phishing lures to move laterally through entire organizations.

Why This Matters

BozokMedia analysis shows that this shift in tactics highlights a growing disparity in regional cyber resilience. The ability of Transparent Tribe to exploit the relatively immature digital infrastructure of Afghanistan provides them with a strategic intelligence foothold, which they can use to launch more complex operations against regional neighbors.

The use of hijacked desktop shortcuts may seem primitive, but it remains a highly effective method for maintaining persistence without triggering modern security alerts.

In contrast, the group's attempts to penetrate Indian government agencies have met with significant resistance. The attackers developed highly tailored phishing paraphernalia aimed at the Ministry of Defense, the Ministry of Foreign Affairs, the Indian Air Force, and the National Informatics Centre (NIC). Despite the sophistication of these lures, no successful compromises have been confirmed within Indian government networks to date.

Technically, the new Patchcord malware is a C++ implant designed to execute arbitrary code directly in-memory, a tactic used to evade traditional disk-based detection. A peculiar aspect of its operation is 'browser shortcut hijacking,' where the malware modifies the victim's desktop icons. When a user clicks their browser icon, the malware executes itself first before launching the browser, ensuring a continuous, hidden presence.

Historical Background

Transparent Tribe's operations in the region date back to at least December 2023, with a notable surge in activity observed in May 2024. Long suspected of being state-sponsored by Pakistan, the group's evolution from basic phishing to utilizing Go-based tools like Sheetcord—which hides command-and-control traffic within Google Sheets—marks a significant advancement in their operational capabilities.

Did You Know?: Some advanced malware uses legitimate cloud services like Google Sheets to communicate with hackers, making the malicious traffic look like normal office work.

Frequently Asked Questions

1. What is Patchcord malware?
Patchcord is a new C++ based backdoor used by Transparent Tribe to run code in-memory and hijack browser shortcuts for persistence.

2. Has India's security been breached by this group?
No. While the group has targeted multiple Indian ministries, there is currently no evidence of any successful compromise.