APT36 Exploits Fake VPN Installers and Google Sheets C2 to Target Afghan Telecom and South‑Asian Critical Infrastructure
What Happened — Acronis’ Threat Research Unit disclosed a new espionage campaign, dubbed PATCHCORD, that delivers a custom C/C++ backdoor to telecom operators in Afghanistan and critical‑infrastructure firms in South Asia. The implant is distributed via counterfeit VPN installers and a Go‑based second stage (SHEETCORD) that uses Google Sheets as its command‑and‑control channel.
Why It Matters for Compliance & Audit Readiness
- The technique bypasses traditional perimeter defenses, highlighting the need for SOC 2 Access Control (CC6.1) policies that enforce least‑privilege and application allow‑listing.
- Persistent shortcut hijacking demonstrates why continuous monitoring of endpoint configurations and audit‑ready logs is essential.
- The use of socially engineered installers underscores the importance of Security Awareness Training as documented evidence for SOC 2 Security (CC7.1).
Who Is Affected — Telecommunications operators, critical‑infrastructure providers, and any organization that distributes internal‑use software in Afghanistan, India, and surrounding regions.
Recommended Actions
- Map the incident to SOC 2 access‑control criteria (CC6.1) and verify that privileged‑access reviews are performed quarterly.
- Deploy endpoint detection and response (EDR) with file‑integrity monitoring to detect shortcut hijacking.
- Enforce application allow‑listing and code‑signing verification for all installer packages.
- Conduct targeted phishing and social‑engineering simulations to reinforce user awareness.
Source: Security Affairs
Technical Notes
- Delivery vector: counterfeit VPN installers (phishing) → Windows 64‑bit backdoor (PATCHCORD).
- Persistence: hijacks Edge, Chrome, Firefox shortcuts, backing up originals.
- C2: Google Sheets (SHEETCORD) used for covert command traffic.
Source: Acronis Threat Research Unit report (linked above)