Spoofed Portal Drops APT36 Backdoor on Telecoms

F5 Labs · High sophistication
Last updated August 19, 2026

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to attacker infrastructure for remote control and persistence.

How the Attack Worked

The APT36 (Transparent Tribe) campaign relied on a spoofed telecom support portal to deliver a malicious Windows installer. The lure presented itself as a required telecom management tool, prompting targets to download and run a file named TMS_AfghanTelecom.exe. This Inno Setup package was not a legitimate update but a delivery mechanism for the PATCHCORD backdoor, which then established persistence through browser shortcut hijacking and reached out to a command-and-control domain, appstoore[.]solutions, for remote access.

Why It Succeeded

The attack worked because it exploited routine IT behavior rather than a technical flaw. Staff in network operations, helpdesk, and engineering roles are accustomed to installing tools and updates as part of their jobs, which made an unsolicited installer request from an external portal feel plausible. The portal itself mimicked a legitimate telecom or NIC support site, and the installer was packaged to resemble a normal software update rather than an obvious threat.

What to Watch For

  • Unexpected or unsolicited requests to install software from an external portal rather than an internal, approved source.
  • Portal domains that closely resemble a real brand but contain subtle misspellings, such as appstoore[.]solutions.
  • Installer files, especially unsigned Inno Setup or other "setup" packages, arriving outside of normal corporate software distribution channels.
  • Any software delivered through a link rather than a known internal update process.

How to Build Resistance

Organizations, particularly in telecommunications and critical infrastructure, should treat any "install this tool from a portal" request as high risk until verified through a known-good internal channel. Security awareness training should specifically cover lookalike domains and misspelled support sites, since attackers rely on quick visual similarity rather than exact duplication. Staff should also be trained to treat unexpected or unsigned installers as suspicious by default and to report them to security teams instead of running them, even when the file name suggests a legitimate business tool. Building this habit of verification before installation is the most direct way to blunt this type of delivery method, since the technique depends entirely on a user choosing to download and execute the file themselves.

Key findings

  • APT36 (Transparent Tribe) used “spoofed delivery portals” and a malicious installer lure to start infections.
  • The lure file was an Inno Setup installer named “TMS_AfghanTelecom.exe” that deployed the PATCHCORD backdoor.
  • PATCHCORD used browser-shortcut hijacking for persistence and communicated with a C2 domain (appstoore[.]solutions).
  • The bulletin also notes other activity (ransomware/vulnerability exploitation), but the clearly simulatable social-engineering workflow is in the APT36 section.

Who’s being targeted

  • Commonly targeted roles: IT, Network Operations, Helpdesk, Engineering, Security Operations (SOC).
  • Affected industries: Telecommunications, Critical infrastructure.
  • Attack channels: website.
  • Impersonated: Telecom support / NIC support portal.

Red flags to watch for

  • Unexpected/unsolicited request to install software from an external portal
  • Portal domain looks similar to a real brand but is slightly misspelled (e.g., appstoore[.]solutions)
  • Installer is not delivered through normal corporate software channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the APT36 spoofed portal attack?

It is a social engineering campaign in which APT36 (Transparent Tribe) used a spoofed telecom support portal to lure targets into downloading a malicious installer named TMS_AfghanTelecom.exe, which deployed the PATCHCORD backdoor.

How did the malware achieve persistence?

PATCHCORD used browser shortcut hijacking for persistence and communicated with a command-and-control domain, appstoore[.]solutions, for remote control.

Who was targeted in this campaign?

The campaign targeted Afghan telecom providers and South Asian critical infrastructure, with relevance to IT, network operations, helpdesk, and engineering staff who handle software installations.

What red flags should staff look for?

Watch for unsolicited requests to install software from an external portal, lookalike or misspelled domains, and installers delivered outside normal corporate software channels.

Read the video transcript

You get a portal saying: “Action required: install the telecom management tool, TMS, from our support site.” Looks routine, right? Behind that download, a group called APT36 drops a fake installer named TMS_AfghanTelecom.exe. Run it, and it quietly plants their PATCHCORD backdoor and phones home to appstoore.solutions. Here’s the trap: the portal looks like telecom support, but the domain is slightly wrong, think appstoore.solutions instead of a real vendor. And this installer isn’t coming from our normal software channel at all. If you’re ever told to install or update a tool from a portal like this, stop and verify it through our internal IT channel before you download anything.

Similar attacks

Fake VPN Installers Hit Afghan Telecom Targets

Fake VPN Installers Hit Afghan Telecom Targets

Acronis reported a real espionage campaign delivering a backdoor (PATCHCORD) to Afghan telecom providers and South Asian critical infrastructure by tricking victims into installing look‑alike VPN and telecom tools. The operation also used cloud services like Google Sheets (and GitHub Gists) to…

August 16, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake Free COD Points Scam Steals Logins and 2FA

Fake Free COD Points Scam Steals Logins and 2FA

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

August 2, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
GST-Themed Phishing Hits India With Remcos RAT

GST-Themed Phishing Hits India With Remcos RAT

A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official GST tax notices. The goal was to trick recipients into opening convincing “refund/compliance” documents that install Remcos RAT to steal…

July 20, 2026