Fake VPN Installers Hit Afghan Telecom Targets

Security Affairs · High sophistication
Last updated August 17, 2026

Acronis reported a real espionage campaign delivering a backdoor (PATCHCORD) to Afghan telecom providers and South Asian critical infrastructure by tricking victims into installing look‑alike VPN and telecom tools. The operation also used cloud services like Google Sheets (and GitHub Gists) to blend command-and-control traffic into normal business activity.

How the attack worked

This campaign relied on fake VPN installers and telecom management tools that impersonated Afghan Telecom (AFTEL). Victims believed they were downloading legitimate software from a trusted telecom provider, but the installer instead delivered a previously undocumented backdoor tracked as PATCHCORD. A second lure used a domain impersonating India's National Informatics Centre (NIC) to distribute related malware to government and critical infrastructure targets.

Once installed, PATCHCORD established persistence in an unusual way: it hijacked browser shortcuts for Edge, Chrome, and Firefox. Every time a victim clicked their browser icon expecting to open the web, the malware ran invisibly in the background first, making the compromise very difficult to notice through normal use.

Why it succeeded

The lures worked because they were built with a high level of fidelity. One installer reportedly matched the real Afghan Telecom company name, product fields, and even the URL of the actual support portal customers use. This level of detail made the fake tool difficult to distinguish from a genuine download, especially for telecom staff who may routinely install vendor or support tools as part of their job.

The attackers also used legitimate cloud services to mask their infrastructure. A related implant, SHEETCORD, used Google Sheets for command-and-control, creating a separate spreadsheet tab for each victim to exchange commands. Another discovered tool used GitHub Gists for the same purpose. Because traffic to Google Sheets and GitHub looks like ordinary business activity, this approach helped the operation blend in rather than trigger obvious network alarms.

What to watch for

  • Software downloads that look correctly branded but do not come from an approved internal portal or verified vendor channel
  • Installers that appear to run normally in the background while something else installs alongside them
  • Unexpected or unusual traffic to cloud services like Google Sheets or GitHub from endpoints that would not normally use them this way
  • Browser shortcuts or icons that seem to behave normally but are followed by unexplained background activity

Building resistance

Organizations, especially in telecom, government, and critical infrastructure, should require that VPN and IT tools only be installed from approved internal software portals or verified vendor sources, not from links or ad hoc support pages. Staff should be trained that realistic branding, matching names, product fields, and even portal URLs, is not proof of legitimacy on its own.

Security teams should also increase attention to cloud-service abuse for command-and-control, treating unusual endpoint use of services like Google Sheets or GitHub as a potential red flag. Finally, encouraging employees to quickly report odd device behavior after any software install, such as delays or unexpected background activity when opening a browser, can help catch this kind of persistence technique before it spreads further.

Key findings

  • Victims were lured into installing “fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.”
  • A second implant (SHEETCORD) used “Google Sheets for C2 communication,” creating a spreadsheet tab per victim to exchange commands.
  • The malware used stealthy persistence by “hijacking browser shortcuts” (Edge/Chrome/Firefox) so the malware runs when a user clicks their browser icon.
  • Researchers also found “HACKERAI C2 Agent” using GitHub Gists for command-and-control and signs of AI-assisted code generation.
  • Acronis assessed the activity as moderately linked to APT36 (Transparent Tribe).

Who’s being targeted

  • Commonly targeted roles: Telecom operations, IT support/helpdesk, Network operations, System administrators, Government IT, Critical infrastructure operations.
  • Affected industries: Telecommunications, Critical infrastructure, Government, Defense, Energy/Utilities.
  • Attack channels: website.
  • Impersonated: Afghan Telecom (AFTEL) support/official VPN provider, India’s National Informatics Centre (NIC).

Red flags to watch for

  • Software download is “branded to look exactly like the real thing” but is not obtained from a verified internal portal or known vendor source
  • Installer “opens normally in the background” to reduce suspicion while installing something else
  • Overly specific “matching the company name, product fields, and even the URL of the real support portal” can be a sign of careful impersonation
  • Lookalike domain impersonating a government IT authority
  • Unexpected request to install software from the web rather than approved software channels
  • No validation step (internal ticket/approval) before installing tools
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the fake VPN installer campaign targeting telecom providers?

Attackers distributed fake VPN installers and telecom management tools impersonating Afghan Telecom (AFTEL) to deliver a custom backdoor tracked as PATCHCORD to telecom providers and South Asian critical infrastructure organizations.

How did the malware maintain persistence on infected systems?

PATCHCORD established persistence by hijacking browser shortcuts, so the malware ran invisibly in the background every time a user clicked their browser icon, before the browser itself opened.

How did the attackers hide their command-and-control traffic?

A second implant, SHEETCORD, abused Google Sheets for command-and-control by creating a spreadsheet tab per victim, while a third malware family used GitHub Gists for the same purpose, blending traffic into normal cloud activity.

Who is suspected to be behind this campaign?

Acronis assessed the activity as moderately linked to APT36 (Transparent Tribe), though attribution remains a suspected connection rather than a confirmed one.

Read the video transcript

Fake VPN installers are hitting real telecoms, one campaign even copied Afghan Telecom’s VPN portal pixel for pixel. You click install, it opens normally in the background, but it’s actually PATCHCORD, malware that hijacks your browser shortcuts and talks to its operators through Google Sheets and GitHub Gists. One installer even matched Afghan Telecom’s company name, product fields, and real support URL text. Another came from a site impersonating India’s National Informatics Centre. The branding is perfect, that’s the trap. If you’re ever asked to install a VPN or IT tool from a website, even one that looks exactly right, stop and only get it from our approved internal software portal.

Similar attacks

Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Mexico ID Site Pushed WebDAV Malware

Fake Mexico ID Site Pushed WebDAV Malware

Researchers found an exposed malware delivery server that contained phishing lures, testing notes, and live delivery logs for an active campaign. The live operation targeted Windows users in Mexico using a fake government ID (CURP) lookup site that triggered a WebDAV-based download flow and…

July 20, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Fake Free COD Points Scam Steals Logins and 2FA

Fake Free COD Points Scam Steals Logins and 2FA

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

August 2, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026