2026-08-17NOTABLEEspionage implants run command-and-control through the Google Sheets API and persist by rewriting browser shortcuts
PATCHCORD
malware · malware:patchcord single-source
Compiled C/C++ Windows backdoor delivered through Inno Setup installers impersonating Afghan Telecom service-management and VPN software and Afghanistan's Ministry of Communications and Information Technology. It persists by rewriting Microsoft Edge, Google Chrome and Mozilla Firefox shortcuts across five locations to launch itself with the real browser path as an argument while preserving the original icon, fingerprints the host, and polls a hardcoded server. Its most consequential command decodes an operator-supplied payload and executes it entirely in memory via VirtualAlloc, VirtualProtect and CreateThread, writing nothing to disk. A different variant, used in what Acronis calls an earlier campaign against India's energy sector in March 2026, carries virtual-machine, debugger, analysis-process and user-input checks that trigger a randomised sleep rather than process termination (Acronis TRU, 2026-08-13).
Coverage
1
first 2026-08-17 → last 2026-08-17
Latest activity
2026-08-17
Espionage implants run command-and-control through the Google Sheets API and persist by rewriting browser…
Peak priority
notable
1 notable
Targets
telco
sectors: telco, energy, public-sector · regions: apac
Sources cited
3
3 hosts
Defender insights
What each entry about PATCHCORD tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
overlaps with
- APT36Acronis TRU assesses at moderate confidence that the activity overlaps with the APT36 cluster or a closely related Pakistan-linked actor; the lab states an overlap, not an attribution
- HACKERAI C2 AgentAcronis states HACKERAI C2 Agent shares multiple capabilities with PATCHCORD and SHEETCORD, differing in its command-and-control transport
- SHEETCORDAcronis records SHEETCORD as combining functionality previously observed in the SHEETCREEP RAT with capabilities introduced in PATCHCORD, on shared operator infrastructure
Story timeline
Hunting pivots
ATT&CK techniques (14 across 6 tactics)
14 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell · User Execution: Malicious File
- PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder · Boot or Logon Autostart Execution: Shortcut Modification
- Privilege EscalationBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder · Boot or Logon Autostart Execution: Shortcut Modification
- StealthDeobfuscate/Decode Files or Information · Virtualization/Sandbox Evasion · Hide Artifacts: Hidden Window · Reflective Code Loading · Debugger Evasion
- DiscoveryProcess Discovery · System Information Discovery · Virtualization/Sandbox Evasion · Debugger Evasion
- Command and ControlApplication Layer Protocol: Web Protocols · Web Service: Bidirectional Communication
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1059.003Command and Scripting Interpreter: Windows Command Shell×1
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
Persistence TA0003
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1547.009Boot or Logon Autostart Execution: Shortcut Modification×1
Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
Privilege Escalation TA0004
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1547.009Boot or Logon Autostart Execution: Shortcut Modification×1
Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
Stealth TA0005
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1497Virtualization/Sandbox Evasion×1
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1564.003Hide Artifacts: Hidden Window×1
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1622Debugger Evasion×1
Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
Discovery TA0007
T1057Process Discovery×1
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1497Virtualization/Sandbox Evasion×1
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1622Debugger Evasion×1
Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
T1102.002Web Service: Bidirectional Communication×1
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.
Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗
Entries about PATCHCORD (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- acronis.com1 (33%)
- securityaffairs.com1 (33%)
- thehackernews.com1 (33%)
All cited sources (3)
- acronis.comAcronis Threat Research Unithttps://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
- securityaffairs.comSecurity Affairshttps://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html