HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

APT36 Deploys PATCHCORD Backdoor via Fake VPN Installers and Google Sheets C2 Against Afghan Telecom and South‑Asian Infrastructure

APT36’s PATCHCORD campaign uses counterfeit VPN installers to drop a custom backdoor on telecom systems, then pivots to a Google‑Sheets C2 stage. The incident highlights gaps in access‑control policies and the need for continuous endpoint monitoring for SOC 2 readiness.

LiveThreat™ Intelligence · 📅 August 16, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

APT36 Exploits Fake VPN Installers and Google Sheets C2 to Target Afghan Telecom and South‑Asian Critical Infrastructure

What Happened — Acronis’ Threat Research Unit disclosed a new espionage campaign, dubbed PATCHCORD, that delivers a custom C/C++ backdoor to telecom operators in Afghanistan and critical‑infrastructure firms in South Asia. The implant is distributed via counterfeit VPN installers and a Go‑based second stage (SHEETCORD) that uses Google Sheets as its command‑and‑control channel.

Why It Matters for Compliance & Audit Readiness

  • The technique bypasses traditional perimeter defenses, highlighting the need for SOC 2 Access Control (CC6.1) policies that enforce least‑privilege and application allow‑listing.
  • Persistent shortcut hijacking demonstrates why continuous monitoring of endpoint configurations and audit‑ready logs is essential.
  • The use of socially engineered installers underscores the importance of Security Awareness Training as documented evidence for SOC 2 Security (CC7.1).

Who Is Affected — Telecommunications operators, critical‑infrastructure providers, and any organization that distributes internal‑use software in Afghanistan, India, and surrounding regions.

Recommended Actions

  • Map the incident to SOC 2 access‑control criteria (CC6.1) and verify that privileged‑access reviews are performed quarterly.
  • Deploy endpoint detection and response (EDR) with file‑integrity monitoring to detect shortcut hijacking.
  • Enforce application allow‑listing and code‑signing verification for all installer packages.
  • Conduct targeted phishing and social‑engineering simulations to reinforce user awareness.

Source: Security Affairs

Technical Notes

  • Delivery vector: counterfeit VPN installers (phishing) → Windows 64‑bit backdoor (PATCHCORD).
  • Persistence: hijacks Edge, Chrome, Firefox shortcuts, backing up originals.
  • C2: Google Sheets (SHEETCORD) used for covert command traffic.

Source: Acronis Threat Research Unit report (linked above)

📰 Original Source
https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →