PATCHCORD: The Fake VPN Installer Hitting Afghan Phone Networks and Indian Infrastructure

A new backdoor is being smuggled onto computers through fake Afghan Telecom software, and researchers say critical services in South Asia are in the crosshairs.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A smartphone displaying a software installation dialog box for a telecom application, with network infrastructure silhouettes visible through a window behind it
Share

Key points

  • Researchers at Acronis Threat Research Unit have named a new backdoor PATCHCORD, spotted in an ongoing campaign against South Asian targets.
  • The malware spreads through fake VPN installers that impersonate Afghan Telecom, the country's state-owned phone company.
  • Confirmed targets include Afghan telecom providers and critical infrastructure organisations in India.
  • PATCHCORD is written in C and C++, compiled to run quietly on Windows machines once the fake installer is opened.
  • The lures are sector-specific: each fake file is tailored to look routine to the exact staff being targeted.

Someone is going after Afghanistan's phone networks and the utilities that keep parts of India running. The tool they're using is new, and it has a name: PATCHCORD.

Security researchers at Acronis, an IT firm that tracks online attacks, say they've watched the campaign unfold over recent weeks. The Hacker News first flagged the write-up. This is a targeted spying operation, not a smash-and-grab.

What is PATCHCORD?

PATCHCORD is a backdoor: a hidden program that gives an attacker remote control of an infected Windows computer. It's written in C and C++, two programming languages that produce small, fast files which sit quietly on a machine without drawing attention. Once installed, the attacker can pull files and issue commands. Think of it as a spare key cut for a house the owner doesn't know has an extra lock.

This is the second trojanised VPN installer we've covered in five weeks. On 5 August we reported on a tampered QuickFox VPN package carrying the FDMTP backdoor. Different target base, same delivery logic.

How are people getting infected?

The hackers are hiding PATCHCORD inside fake VPN installers. A VPN, or virtual private network, encrypts your internet connection. Telecom staff use them constantly to reach work systems remotely.

The fake installer pretends to be from Afghan Telecom. An engineer downloading what looks like a routine tool from their own employer has little reason to hesitate. That's the point.

The failure mode is familiar: brand-name trust doing the job that a signature check should be doing.

Who is being targeted?

Target Country Lure used
Telecom providers Afghanistan Fake Afghan Telecom VPN installer
Critical infrastructure India Sector-specific fake software

Critical infrastructure is the shorthand for organisations a country can't function without: electricity, water, telecoms, transport. When attackers craft bespoke lures for these sectors, it usually points to a state-backed operation rather than criminals chasing a quick payout. Acronis hasn't publicly attributed the campaign to a specific government or group.

Acronis flagged a separate threat in July too. Our report on their AI-assistant ransomware warning is worth reading alongside this, because the common thread is attackers exploiting trusted software channels before defenders think to check them.

Should ordinary people be worried?

Not directly. PATCHCORD isn't being sprayed at the public through spam. It's aimed at staff inside specific organisations.

The downstream risk is real, though. Attackers sitting quietly inside a telecom company for months can read call records and track who talks to whom. In Afghanistan, that means most of the country is exposed to whatever the attacker decides to do with that access.

If you work for a telecom or utility in the region, don't install VPN software that arrives by email or chat link. Get it from your IT team directly. If something already installed is behaving oddly, flag it today.

The post-mortem will note that the installer looked legitimate because nobody checked whether it was. If your fleet trusts any binary carrying a familiar brand name, you don't have application control: you have a suggestion box.

© 2026 Threat Vectr