Pakistan's Transparent Tribe Is Spying on Afghan Telecom Workers With Fresh Malware
A Pakistani hacking group has been quietly breaking into government and telecom targets in Afghanistan using two newly documented tools. India was in their sights too, but appears to have held the line.

Key points
- Transparent Tribe, a Pakistan-linked hacking group, has been running active spying operations against Afghan government and telecom targets since at least December 2024.
- Two new malware tools named Patchcord and Sheetcord were documented by researchers at Acronis in 2025.
- One confirmed victim is an IT officer at Afghan Telecom (AFTEL), whose WhatsApp messages and desktop files were stolen.
- Transparent Tribe also built fake login pages and documents aimed at India's Ministry of Defence, Ministry of Foreign Affairs, and the Indian Air Force, but no successful break-ins there have been confirmed.
- India's national cyber-response team, CERT-In, largely handles these attacks by blocking the group's known server addresses.
A Pakistani hacking group has been running a quiet, patient spying campaign across Afghanistan, and researchers say it is still going. The group, known as Transparent Tribe or APT 36, has long been suspected of working on behalf of the Pakistani government, based on who it targets and how it operates. This year it showed up with sharper tools.
Researchers at Acronis, first reported in detail by Dark Reading, documented two new pieces of malware, called Patchcord and Sheetcord, being used in the campaign.
How did the hackers get in?
They started with phishing: fake emails and documents designed to look like tools their targets already trusted. Lures impersonated network software used by a major Afghan telecoms company, a fuel-management tool used in India's energy sector, and government employee benefit portals. Once a victim opened the right file, Patchcord installed itself silently.
Patchcord is a backdoor, meaning a hidden program that gives the hackers remote access to an infected computer. It can run secret instructions, take stock of what software is running, and resist basic analysis tools. Its sneakiest trick, though, is an old one: browser shortcut hijacking.
Here is how that works. Every time you click the Chrome or Edge icon on your desktop to open a browser, Patchcord quietly rewrites that shortcut so it runs the malware first, then opens the browser as normal. You see nothing different. But every click hands the malware another chance to run in the background.
It is a well-known technique, and most modern endpoint security products, the software companies use to monitor devices for threats, catch it. That raises a question about why a sophisticated group would bother with it at all.
Acronis senior threat researcher Subhajeet Singha has a straightforward answer: the targets do not have much better protection in place, so there is no need for anything fancier. "I think they did nice recon on their targets, what they use, what antivirus product they have, and depending on that they use this technique," he said.
Who was actually hit?
At least two confirmed victims are in Afghanistan. One is an unnamed Afghan subsidiary of an international company. The other is an IT officer at the Khost branch of Afghan Telecom, the state-owned national carrier. According to Singha, the hackers were "stealing data from his desktop and looking into his WhatsApp and private data," then using that material to build more convincing fake files to phish other employees at the same company.
The campaign also used a third tool, called HackerAI, which Acronis believes was built with the help of an AI coding assistant. It is less polished than Patchcord but functional enough for targets with limited defences.
| Tool | Type | Notable feature | Status |
|---|---|---|---|
| Patchcord | C++ backdoor | Browser shortcut hijacking for persistence | Active since at least March 2025 |
| Sheetcord | Go-based backdoor | Hides traffic through Google Sheets | Active |
| HackerAI | Malware framework | Likely AI-assisted; uses GitHub Gist for control | Active |
Should Afghan telecom customers be worried?
If you use Afghan Telecom services, this campaign targets the company's staff, not its customers directly. That said, stolen internal data can fuel further attacks. Anyone working in Afghan government or telecoms should treat unexpected documents or login prompts with real scepticism, and report anything odd to their IT team immediately.
For everyone else, the practical lesson is the same one it always is: be careful about opening attachments from unfamiliar senders, and make sure the security software on your work computer is up to date.



