CYBERSECURITYTRACKER
TRACKING
Permanent story citation

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4525

As cited

Copy frozen at (site build).

threat intel

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

A newly discovered backdoor named PATCHCORD targets Afghan telecom providers and South Asian critical infrastructure through sector-specific lures such as fake VPN installers impersonating legitimate telecom software. Acronis Threat Research Unit identified the backdoor as a compiled C/C++ implant, suggesting a focused campaign with customized delivery mechanisms.

Why it matters: Telecom operators and critical infrastructure organizations in Afghanistan and South Asia face direct compromise risk; practitioners should review network logs for suspicious VPN installer activity and implement application whitelisting to block unauthorized binaries.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

A new backdoor named PATCHCORD is being deployed in an active campaign targeting Afghan telecom providers and Indian critical infrastructure. The implant, written in C/C++, is delivered via sector-specific lures such as fake virtual private network installers impersonating Afghan Telecom.

Why it matters: Telecom and critical infrastructure operators in Afghanistan and India should check for indicators of PATCHCORD compromise and review recent VPN installer deployments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary