Pakistani Threat Actor Transparent Tribe Deploys New Malware Against Afghan Targets
A refreshed toolset including Patchcord and Sheetcord has breached Afghan telecom infrastructure while failing to penetrate Indian government defenses.
The Pakistani threat actor Transparent Tribe, also known as APT36, has launched a cyber espionage campaign targeting government and telecommunications entities in Afghanistan and India. The operation utilizes a refreshed suite of malware to infiltrate high-value targets, revealing a significant gap in regional cybersecurity resilience.
According to reports from Dark Reading, the group deployed a new C++ implant called Patchcord and a Go-based evolution known as Sheetcord, alongside a related remote access trojan (RAT) called Sheetcreep. Patchcord achieves persistence on infected systems through a browser shortcut hijacking mechanism. Sheetcord utilizes Windows startup processes for persistence and masks its command-and-control (C2) traffic by routing it through Google Sheets to evade detection.
Regional Disparity in Defense
The campaign has seen varying levels of success depending on the target's location. In Afghanistan, the group successfully compromised several targets, including an Afghan subsidiary of an international firm and an IT officer at the Khost branch of the state-owned Afghan Telecom (AFTEL).
In contrast, attempts to breach Indian government agencies were largely unsuccessful. Transparent Tribe targeted several high-profile entities, including the Indian Air Force, the National Informatics Centre, and the Ministries of Defense and Foreign Affairs. However, no successful compromises were confirmed in India, as the group encountered superior cybersecurity defenses.
The Strategic Context
Transparent Tribe is a suspected Pakistan-based group active since at least 2013. It primarily targets diplomatic, defense, and research organizations within India and Afghanistan and is widely believed to operate on behalf of Pakistani state intelligence operations.
This latest campaign underscores a stark disparity in cybersecurity maturity between the two neighboring nations. While India's government agencies—supported by CERT-In—effectively blocked the group's known infrastructure, the Afghan targets proved far more vulnerable. Subhajeet Singha, a senior threat researcher at Acronis, noted that because cybersecurity maturity in the region is not yet sufficient, attackers can effectively "spin up a vibecoded malware and do their work."
Industry Implications
The use of relatively low-grade tactics, such as shortcut hijacking, suggests that APT36 is "playing down to the competition" in Afghanistan, where defenses are immature. This allows the group to maintain operational success without needing the sophisticated stealth required to bypass the "wall" of defenses found in India. For the broader industry, this highlights how threat actors calibrate their toolsets based on the perceived weakness of the target's environment rather than using a one-size-fits-all approach.
What's Next
Security analysts are now monitoring the group's use of a third framework called 'HackerAI,' which is believed to be generated using AI coding tools and utilizes GitHub Gists for C2 communication. As Transparent Tribe continues to iterate its toolset, the focus remains on whether the group will develop more sophisticated methods to penetrate Indian defenses or continue to exploit the vulnerabilities of less-protected regional entities.