Published: · Region: South Asia · Category: cyber

New PATCHCORD Malware Campaign Targets Afghan Telecom and South Asian Critical Infrastructure

Researchers have identified a new custom backdoor, dubbed PATCHCORD, in an ongoing campaign against Afghan telecom providers and critical infrastructure organisations in South Asia. The operation uses sector-specific delivery methods and raises concerns about stealthy access to the networks that keep essential services running in fragile states.

Cybersecurity researchers have uncovered a new malware campaign targeting some of South Asia’s most sensitive networks, from Afghan telecommunications to critical infrastructure in neighbouring countries.

According to Acronis’s Threat Research Unit, the operation delivers a previously undocumented custom backdoor named PATCHCORD against Afghan telecom providers and critical infrastructure organisations elsewhere in South Asia. The backdoor is described as a compiled C/C++ implant, indicating a purpose-built tool rather than off-the-shelf malware, and is delivered using sector-specific methods tailored to its targets.

Telecom networks in Afghanistan are a central communication channel for civilians, humanitarian groups and the authorities. A successful compromise of core systems can expose call records, location data and messaging patterns for large numbers of users, and create options for surveillance or service disruption. By focusing on telecom operators, PATCHCORD’s operators gain a vantage point over a broad slice of society and state activity.

Beyond Afghanistan, the campaign’s reach into South Asian critical infrastructure suggests an interest in utilities and services that underpin daily life and state functions. In such environments, a backdoor does not need to cause an immediate outage to be valuable. Simply maintaining access inside networks that monitor or control industrial processes allows attackers to map systems, identify weak points and retain options for future leverage, whether for intelligence-gathering or potential sabotage.

For engineers and staff in these sectors, the threat may arrive through a familiar vector such as a targeted email or an update to a specialist application. Once inside, attackers can move slowly and use legitimate administrative tools to blend in with normal network activity, making detection difficult without dedicated monitoring.

Attribution has not been publicly assigned in the available reporting. However, the choice of targets—telecoms and critical infrastructure across borders—matches the typical priorities of state-linked intelligence services or advanced criminal groups. The value lies not only in any data stolen now, but in preserving the ability to disrupt or pressure these systems if a political or security crisis escalates.

Indicators to watch include technical advisories from governments or major telecom and infrastructure operators, evidence that PATCHCORD or related tools are being used in additional countries, and any shift from quiet access toward overt disruption. Concrete moves by South Asian states to strengthen industrial and telecom network security and to share incident information would signal that the campaign is being treated as a strategic risk, not just a technical problem.

Sources