Uncovering APT36: A South Asian Telecoms Malware Cluster (2026)

APT36-Linked Malware Cluster Targets South Asia Telecoms: A Deep Dive into the Operator's Evolution

The APT36-linked malware cluster targeting South Asian telecommunications providers and critical infrastructure organizations is a sophisticated operation that showcases the group's ongoing evolution. This article delves into the cluster's composition, targeting patterns, and the implications for the region's cybersecurity landscape.

The Malware Cluster: A Complex Web

The cluster comprises three previously undocumented malware families: PATCHCORD, SHEETCORD, and HACKERAI C2 Agent. Each family employs unique techniques to establish persistence, fingerprint infected machines, and communicate with command-and-control servers.

  • PATCHCORD: A custom C and C++ backdoor delivered through malicious Inno Setup installers. It impersonates legitimate tools like an Afghan telecom management application and an Indian energy client. Once installed, it hijacks browser shortcuts, fingerprints machines, and executes remote shell commands.
  • SHEETCORD: A Go-based implant using Google Sheets for command-and-control. It targets six browsers and employs VBScript to rewrite shortcuts. Distributed through a domain impersonating India's National Informatics Centre, it adds a startup folder script and registry run key for persistence.
  • HACKERAI C2 Agent: Pre-dating the other families, this implant uses GitHub Gists for communication. It contains code comments and debugging messages suggesting AI-assisted development. Linked to a domain impersonating India's Controller General of Defence Accounts.

Targeting Patterns: A Broadening Campaign

The campaign's targeting patterns indicate a shift over time, with a focus on diverse sectors:

  • Afghan Telecom Providers: Valuable espionage targets due to their access to communications infrastructure, subscriber data, and official communications.
  • Indian Government Agencies: Including the National Informatics Centre and the Ministry of Defence.
  • Energy Sector: Lures related to India's National Hydroelectric Power Corporation (NHPC).
  • Indian Defence Personnel: Targeted through defence-themed lures.
  • Healthcare: A Delhi healthcare provider was also impersonated.

Implications and Future Developments

The exposed server contained exploit tooling for CVE-2024-6387 (regreSSHion) and CVE-2021-4034 (PwnKit), suggesting a multi-vector attack strategy. The presence of SuperShell, Metasploit, and browser credential-harvesting tools further emphasizes the operator's intent to combine phishing with system exploitation.

The Operator's Evolution: A Concern

The discovery of these malware families highlights the operator's evolution, moving from custom C/C++ backdoors to Go-based implants that abuse legitimate cloud services. This evolution makes detection and attribution more challenging, as the malware adapts to blend into normal business activity.

Conclusion: A Call for Enhanced Cybersecurity

The APT36-linked malware cluster poses a significant threat to South Asian telecommunications and critical infrastructure. Its sophisticated techniques, evolving targeting patterns, and multi-vector attack strategy demand heightened vigilance and proactive cybersecurity measures from organizations and governments alike.

This incident underscores the importance of continuous monitoring, threat intelligence sharing, and adaptive security strategies to counter sophisticated cyber threats.

Uncovering APT36: A South Asian Telecoms Malware Cluster (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Frankie Dare

Last Updated:

Views: 6252

Rating: 4.2 / 5 (53 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Frankie Dare

Birthday: 2000-01-27

Address: Suite 313 45115 Caridad Freeway, Port Barabaraville, MS 66713

Phone: +3769542039359

Job: Sales Manager

Hobby: Baton twirling, Stand-up comedy, Leather crafting, Rugby, tabletop games, Jigsaw puzzles, Air sports

Introduction: My name is Frankie Dare, I am a funny, beautiful, proud, fair, pleasant, cheerful, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.