PATCHCORD: The Fake VPN Installer Hitting Afghan Phone Networks and Indian Infrastructure

A new backdoor is being smuggled onto computers through fake Afghan Telecom software, and researchers say critical services in South Asia are in the crosshairs.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial shot of a dimly lit server rack in a utility control room, focus on a network router with blinking amber status LEDs and tangled
Share

Key points

  • Researchers at Acronis Threat Research Unit have named a new backdoor PATCHCORD, spotted in an ongoing campaign against South Asian targets.
  • The malware is being spread through fake VPN installers that pretend to be from Afghan Telecom, the country's state-owned phone company.
  • Confirmed targets so far include Afghan telecom providers and critical infrastructure organisations in India.
  • PATCHCORD is written in C and C++, compiled to run quietly on Windows machines once the fake installer is opened.
  • The lures are sector-specific, meaning each fake file is tailored to look normal to the exact staff being targeted.

Someone is going after the phone networks in Afghanistan and the plants, grids and utilities that keep parts of India running. The tool they are using is new, and it has a name: PATCHCORD.

Security researchers at Acronis, an IT firm that tracks online attacks, say they have watched the campaign unfold over recent weeks. The Hacker News first flagged the write-up. In practice, this is a targeted spying operation, not a smash-and-grab.

What is PATCHCORD?

PATCHCORD is a backdoor, meaning a hidden program that gives an attacker remote control of an infected computer. It is written in C and C++, two programming languages that produce small, fast files which sit comfortably on a Windows PC without drawing attention.

Once it lands, the attacker can browse files, run commands, and pull data back out. Think of it as a spare key cut for a house the owner does not know has an extra lock.

How are people getting infected?

The hackers are hiding PATCHCORD inside fake VPN installers. A VPN, or virtual private network, is a piece of software that encrypts your internet connection, and telecom staff use them constantly to reach work systems from outside the office.

The fake installer pretends to be from Afghan Telecom, the state-owned phone provider. An engineer downloading what looks like a routine tool from their own employer would have very little reason to hesitate. That is the point.

The failure mode here is a familiar one: trust in a brand name doing the job that a signature check should be doing.

Who is being targeted?

Target Country Lure used
Telecom providers Afghanistan Fake Afghan Telecom VPN installer
Critical infrastructure India Sector-specific fake software

Critical infrastructure is the shorthand security people use for the organisations a country cannot function without: electricity, water, transport, telecoms. When attackers spend time crafting bespoke lures for these sectors, it usually points to a state-backed operation rather than criminals chasing a quick payout.

Acronis has not publicly attributed the campaign to a specific government or group yet.

Should ordinary people be worried?

Not directly, no. PATCHCORD is not being sprayed at the general public through spam. It is being aimed at staff inside specific companies.

The knock-on effect is what matters. If attackers sit quietly inside a telecom company for months, they can read call records, track who talks to whom, and potentially disrupt service. Anyone who uses that network, which in Afghanistan means most of the country, is downstream of that risk.

If you work for a telecom or utility in the region, do not install VPN software or updates that arrive by email or chat link. Get it from your IT team directly, and if something already installed is behaving oddly, flag it now, not on Monday.

One thing the post-mortem will say: the installer looked legitimate because nobody was checking whether it actually was.

Operational takeaway: if your fleet trusts any signed binary that carries a familiar brand, you do not have application control, you have a suggestion box.

© 2026 Threat Vectr