PATCHCORD Backdoor Found Using Google Sheets as C2 in Cyber Espionage Campaign

Views: 88 views

447/69 Tuesday, August 18, 2026

Security researchers have disclosed a cyber espionage campaign using a backdoor malware named PATCHCORD, targeting telecommunications providers in Afghanistan and critical infrastructure organizations in South Asia. The attackers used fake VPN installers and telecommunications management tools disguised to appear as software used by the target organizations, tricking users into installing the malware. Researchers stated that the campaign may be linked to APT36, also known as Transparent Tribe.

PATCHCORD is developed in C/C++ and establishes persistence by modifying browser shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox. This allows the malware to run when users open their browsers before launching the legitimate browser as normal. PATCHCORD can also communicate with a command-and-control (C2) server, adjust connection intervals, inspect running processes, execute system commands, and run shellcode in memory.

Analysis of the related infrastructure also identified malware named SHEETCORD, which is developed in Go and uses the Google Sheets API as a command-and-control (C2) channel. It creates a separate tab for each victim machine to receive commands and return results. Researchers also found a HACKERAI C2 agent that uses GitHub Gists for C2 communication, along with evidence suggesting that parts of the code may have been developed using tools based on large language models (LLMs). Organizations should monitor for VPN applications and management tools obtained from untrusted sources, and inspect browser shortcuts and connections to cloud services for anomalies that may be associated with this activity.

Source: https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html