New PATCHCORD Cyber Campaign Hits Afghan Telecom and South Asian Critical Infrastructure
Security researchers have uncovered an ongoing campaign using a custom backdoor, dubbed PATCHCORD, against Afghan telecom providers and South Asian critical infrastructure organizations. Delivered through tailored phishing and masquerading as legitimate admin tools, the operation shows how state‑level tradecraft is seeping into attacks on civilian networks that keep entire economies running.
The same cables that carry phone calls and data across South Asia are now potential pathways for a new kind of intrusion.
Cybersecurity researchers have identified an active hacking campaign that is targeting Afghan telecommunications providers and critical infrastructure organizations across South Asia with a previously undocumented backdoor they call PATCHCORD. The implant, written in C and C++, is being delivered through highly tailored phishing emails and sector-specific lure documents that are designed to tempt administrators and technical staff into opening booby-trapped files.
Once installed, PATCHCORD gives attackers persistent remote access to compromised systems. The backdoor can execute commands, move laterally across networks and exfiltrate sensitive data, according to the analysis. Investigators say the malware often masquerades as legitimate administrative tools, making it harder for overworked defenders in telecom and infrastructure firms to spot before it has done damage. Because the campaign is ongoing, researchers have withheld some indicators of compromise to avoid tipping off the operators, but they describe the tradecraft as consistent with a well-resourced, possibly state-aligned group.
For the people who depend on these networks, the stakes are deeply practical. Telecom companies in Afghanistan underpin everything from mobile banking and remittances to emergency services, news distribution and simple family communication. Power grids, water systems and transport networks in South Asia—some of the campaign’s reported targets—rely on digital control systems that, if compromised, can be shut down, misdirected or used as leverage for extortion. Most users will never hear the name PATCHCORD, but they will feel the consequences if their calls fail during a crisis or utilities mysteriously go offline.
Operationally, the campaign reflects a broader trend: attackers are focusing not just on headline-grabbing government ministries, but on the private and semi-public entities that quietly keep countries functioning. By going after telecoms and other infrastructure operators, hackers gain vantage points that can be used for espionage, traffic interception or the preparatory mapping of systems for potential future sabotage. The use of sector-themed phishing material shows that the operators have taken time to understand their targets’ workflows and pain points.
Strategically, the PATCHCORD activity increases the cyber pressure on a region already facing physical instability and geopolitical competition. Afghanistan’s fragile institutions and limited cybersecurity resources make its networks an attractive testing ground or stepping stone to other targets. Neighboring South Asian states, juggling their own political and economic challenges, must now allocate scarce attention and budgets to defending critical systems against threats that may originate far beyond their borders. The line between classic espionage and potential attacks on civilian infrastructure grows thinner with each such campaign.
The shareable insight is clear: when hackers quietly sit inside a telecom switch or power control room, they hold a form of power that crosses borders faster than any armored column.
Key signals to watch include whether regional telecoms and utilities begin to disclose breaches or service disruptions tied to PATCHCORD, whether any government publicly attributes the campaign to a specific state or group, and how quickly defensive guidance and mitigations spread through South Asia’s infrastructure operators. The discovery of related tools—such as kernel-level rootkits like those recently unveiled in other backdoor families—would indicate an escalating willingness by the attackers to burrow deeper into the systems that keep the region’s lights on and lines open.
Sources
- OSINT