Threat Advisory

Afghan Telecom Providers Targeted by PATCHCORD Backdoor and SHEETCORD Implant

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat activity involves a multi-stage intrusion vector delivering custom backdoor implants to compromise regional telecommunications providers along with critical infrastructure, government, and defense targets. Delivery is primarily facilitated through social engineering lures, such as malicious installers wrapped in archive files that impersonate legitimate telecommunication tracking software, virtual private network setup tools, and utility management clients. Once deployed, the primary objective centers on long-term covert cyber espionage, providing persistent unauthorized remote access, operational reconnaissance, and exfiltration pathways within sensitive operational networks. The affected systems primarily consist of enterprise Windows endpoints and server infrastructure hosting administrative and communication operations. Compromising these environments presents high operational and business risks, potentially granting threat actors deep access to core communications infrastructure, internal routing controls, organizational records, and sensitive government communications. Such access undermines network integrity, exposes confidential data streams, and facilitates downstream operational disruptions across targeted sectors.

The campaign relies on compiled implants written in C/C++, Go, and AI-assisted scripts to establish persistence, perform host reconnaissance, and execute arbitrary commands. Initial execution begins when a malicious setup file extracts a primary payload, which checks for elevated privileges and establishes persistence by modifying registry run keys and hijacking browser shortcut files across multiple browser suites. In its execution flow, the implant preserves user experience by spawning the authentic browser binary in the foreground while executing malicious routines in the background. The implant fingerprints host systems by querying registry keys for operating system edition details, process identifiers, hostnames, and running process lists. Communications with command-and-control nodes leverage distinct channels, including custom HTTP polling mechanisms using base64 and XOR encoding, Google Sheets API v4 endpoints utilizing hardcoded service accounts, and dedicated GitHub Gists for tasking. Command capabilities include process enumeration, execution of arbitrary commands via command-line interpreters or script host processes, interactive control over shortcut hijacking routines, and in-memory shellcode execution utilizing dynamic API calls to allocate memory, alter permissions, and create isolated execution threads without writing artifacts to disk. Additionally, variants incorporate anti-analysis measures, including virtualization checks, debugger detection, sandbox delay loops, and active process monitoring for analysis tools.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat activity involves a multi-stage intrusion vector delivering custom backdoor implants to compromise regional telecommunications providers along with critical infrastructure, government, and defense targets. Delivery is primarily facilitated through social engineering lures, such as malicious installers wrapped in archive files that impersonate legitimate telecommunication tracking software, virtual private network setup tools, and utility management clients. Once deployed, the primary objective centers on long-term covert cyber espionage, providing persistent unauthorized remote access, operational reconnaissance, and exfiltration pathways within sensitive operational networks. The affected systems primarily consist of enterprise Windows endpoints and server infrastructure hosting administrative and communication operations. Compromising these environments presents high operational and business risks, potentially granting threat actors deep access to core communications infrastructure, internal routing controls, organizational records, and sensitive government communications. Such access undermines network integrity, exposes confidential data streams, and facilitates downstream operational disruptions across targeted sectors.

The campaign relies on compiled implants written in C/C++, Go, and AI-assisted scripts to establish persistence, perform host reconnaissance, and execute arbitrary commands. Initial execution begins when a malicious setup file extracts a primary payload, which checks for elevated privileges and establishes persistence by modifying registry run keys and hijacking browser shortcut files across multiple browser suites. In its execution flow, the implant preserves user experience by spawning the authentic browser binary in the foreground while executing malicious routines in the background. The implant fingerprints host systems by querying registry keys for operating system edition details, process identifiers, hostnames, and running process lists. Communications with command-and-control nodes leverage distinct channels, including custom HTTP polling mechanisms using base64 and XOR encoding, Google Sheets API v4 endpoints utilizing hardcoded service accounts, and dedicated GitHub Gists for tasking. Command capabilities include process enumeration, execution of arbitrary commands via command-line interpreters or script host processes, interactive control over shortcut hijacking routines, and in-memory shellcode execution utilizing dynamic API calls to allocate memory, alter permissions, and create isolated execution threads without writing artifacts to disk. Additionally, variants incorporate anti-analysis measures, including virtualization checks, debugger detection, sandbox delay loops, and active process monitoring for analysis tools.[emaillocker id="1283"]

The observed threat activity highlights an evolving operational approach to cyber espionage against critical regional targets. By incorporating multiple bespoke implant families and adopting varied command-and-control channels, the threat actor demonstrates an ability to maintain persistent access while bypassing traditional network defenses and signature-based detection mechanisms. The staging of exploitation frameworks, credential harvesting utilities, and interactive management panels points to broad operational goals that extend beyond endpoint infection to include infrastructure disruption and deep network access. In the broader threat landscape, this activity illustrates the increasing reliance on living-off-the-land techniques, cloud service abuse for command and control, and low-artifact execution chains. The strategic targeting of core telecommunications and government infrastructure reinforces how adversary operations continue to prioritize critical access points to collect intelligence across regional communication channels.

RECOMMENDATION:

We recommend you to update Inno Setup to version 1.0.24.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.006 Command and Scripting Interpreter Python
Persistence T1137 Office Application Startup -
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Discovery T1082 System Information Discovery -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu