Pakistan's Transparent Tribe Is Spying on Afghan Telecom Workers With Fresh Malware
A Pakistani hacking group has been quietly breaking into government and telecom targets in Afghanistan using two newly documented tools. India was in their sights too, but appears to have held the line.

Key points
- Transparent Tribe, a Pakistan-linked hacking group, has been running active spying operations against Afghan government and telecom targets since at least December 2024.
- Two new malware tools, Patchcord and Sheetcord, were documented by researchers at Acronis in 2025.
- One confirmed victim is an IT officer at Afghan Telecom (AFTEL), whose WhatsApp messages and desktop files were stolen.
- Transparent Tribe also built fake login pages and documents aimed at India's Ministry of Defence, Ministry of Foreign Affairs, the National Informatics Centre, and the Indian Air Force, but no successful break-ins there have been confirmed.
- India's national cyber-response team, CERT-In, largely handles these attacks by blocking the group's known server addresses.
A Pakistani hacking group has been running a quiet, patient spying campaign across Afghanistan, and researchers say it's still going. The group, known as Transparent Tribe or APT 36, has long been suspected of working on behalf of the Pakistani government, based on who it targets and how it operates. This year it showed up with sharper tools.
Researchers at Acronis, first reported in detail by Dark Reading, documented two new pieces of malware, Patchcord and Sheetcord, being used in the campaign. We first covered Patchcord on 17 August in "PATCHCORD: The Fake VPN Installer Hitting Afghan Phone Networks and Indian Infrastructure".
How did the hackers get in?
They started with phishing: fake emails and documents designed to look like tools their targets already trusted. Lures impersonated network software used by a major Afghan telecoms company, a fuel-conservation tool used in India's energy sector, and government employee benefit portals. Once a victim opened the right file, Patchcord installed itself silently.
Patchcord is a backdoor, meaning a hidden program that gives hackers remote access to an infected computer. It can run secret instructions, take stock of what software is running, and resist basic analysis tools. Its most distinctive trick, though, is an old one: browser shortcut hijacking.
Every time you click the Chrome or Edge icon on your desktop, Patchcord quietly rewrites that shortcut so it runs the malware first, then opens the browser as normal. You see nothing different. But every click hands the malware another chance to run in the background.
It's a well-known technique, and most modern endpoint security products catch it. That raises a question about why a sophisticated group would bother with it at all.
Acronis senior threat researcher Subhajeet Singha has a straightforward answer: the targets don't have much better protection in place, so there's no need for anything fancier. "I think they did nice recon on their targets, what they use, what antivirus product they have, and depending on that they use this technique," he told Dark Reading.
Who was actually hit?
At least two confirmed victims are in Afghanistan. One is an unnamed Afghan subsidiary of an international company. The other is an IT officer at the Khost branch of Afghan Telecom, the state-owned national carrier. According to Singha, the hackers were "stealing data from his desktop and looking into his WhatsApp and private data," then using that material to build more convincing fake files to phish other employees at the same company.
The campaign also used a third tool, HackerAI, which Acronis believes was built with the help of an AI coding assistant. It's less polished than Patchcord but functional enough for targets with limited defences. Singha put it plainly: in Afghanistan, "they could just spin up a vibecoded malware and do their work."
| Tool | Type | Notable feature | Status |
|---|---|---|---|
| Patchcord | C++ backdoor | Browser shortcut hijacking for persistence | Active since at least March 2025 |
| Sheetcord | Go-based backdoor | Hides traffic through Google Sheets | Active |
| HackerAI | Malware framework | Likely AI-assisted; uses GitHub Gist for control | Active |
Should Afghan telecom customers be worried?
This campaign targets company staff, not customers directly. Stolen internal data can fuel further attacks, though, so anyone working in Afghan government or telecoms should treat unexpected documents or login prompts with real scepticism and report anything odd to their IT team.
For the rest of us, the practical lesson is the same one it always is: be careful about opening attachments from unfamiliar senders, and keep your work computer's security software current. The real story here isn't the cleverness of the tooling, it's that basic defences are still absent enough in the targets that Transparent Tribe doesn't need to be clever at all.



