The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to attacker infrastructure for remote control and persistence.
How the Attack Worked
The APT36 (Transparent Tribe) campaign relied on a spoofed telecom support portal to deliver a malicious Windows installer. The lure presented itself as a required telecom management tool, prompting targets to download and run a file named TMS_AfghanTelecom.exe. This Inno Setup package was not a legitimate update but a delivery mechanism for the PATCHCORD backdoor, which then established persistence through browser shortcut hijacking and reached out to a command-and-control domain, appstoore[.]solutions, for remote access.
Why It Succeeded
The attack worked because it exploited routine IT behavior rather than a technical flaw. Staff in network operations, helpdesk, and engineering roles are accustomed to installing tools and updates as part of their jobs, which made an unsolicited installer request from an external portal feel plausible. The portal itself mimicked a legitimate telecom or NIC support site, and the installer was packaged to resemble a normal software update rather than an obvious threat.
What to Watch For
- Unexpected or unsolicited requests to install software from an external portal rather than an internal, approved source.
- Portal domains that closely resemble a real brand but contain subtle misspellings, such as appstoore[.]solutions.
- Installer files, especially unsigned Inno Setup or other "setup" packages, arriving outside of normal corporate software distribution channels.
- Any software delivered through a link rather than a known internal update process.
How to Build Resistance
Organizations, particularly in telecommunications and critical infrastructure, should treat any "install this tool from a portal" request as high risk until verified through a known-good internal channel. Security awareness training should specifically cover lookalike domains and misspelled support sites, since attackers rely on quick visual similarity rather than exact duplication. Staff should also be trained to treat unexpected or unsigned installers as suspicious by default and to report them to security teams instead of running them, even when the file name suggests a legitimate business tool. Building this habit of verification before installation is the most direct way to blunt this type of delivery method, since the technique depends entirely on a user choosing to download and execute the file themselves.
Key findings
- APT36 (Transparent Tribe) used “spoofed delivery portals” and a malicious installer lure to start infections.
- The lure file was an Inno Setup installer named “TMS_AfghanTelecom.exe” that deployed the PATCHCORD backdoor.
- PATCHCORD used browser-shortcut hijacking for persistence and communicated with a C2 domain (appstoore[.]solutions).
- The bulletin also notes other activity (ransomware/vulnerability exploitation), but the clearly simulatable social-engineering workflow is in the APT36 section.
Who’s being targeted
- Commonly targeted roles: IT, Network Operations, Helpdesk, Engineering, Security Operations (SOC).
- Affected industries: Telecommunications, Critical infrastructure.
- Attack channels: website.
- Impersonated: Telecom support / NIC support portal.
Red flags to watch for
- Unexpected/unsolicited request to install software from an external portal
- Portal domain looks similar to a real brand but is slightly misspelled (e.g., appstoore[.]solutions)
- Installer is not delivered through normal corporate software channels
Frequently asked questions
What is the APT36 spoofed portal attack?
It is a social engineering campaign in which APT36 (Transparent Tribe) used a spoofed telecom support portal to lure targets into downloading a malicious installer named TMS_AfghanTelecom.exe, which deployed the PATCHCORD backdoor.
How did the malware achieve persistence?
PATCHCORD used browser shortcut hijacking for persistence and communicated with a command-and-control domain, appstoore[.]solutions, for remote control.
Who was targeted in this campaign?
The campaign targeted Afghan telecom providers and South Asian critical infrastructure, with relevance to IT, network operations, helpdesk, and engineering staff who handle software installations.
What red flags should staff look for?
Watch for unsolicited requests to install software from an external portal, lookalike or misspelled domains, and installers delivered outside normal corporate software channels.
Read the video transcript
You get a portal saying: “Action required: install the telecom management tool, TMS, from our support site.” Looks routine, right? Behind that download, a group called APT36 drops a fake installer named TMS_AfghanTelecom.exe. Run it, and it quietly plants their PATCHCORD backdoor and phones home to appstoore.solutions. Here’s the trap: the portal looks like telecom support, but the domain is slightly wrong, think appstoore.solutions instead of a real vendor. And this installer isn’t coming from our normal software channel at all. If you’re ever told to install or update a tool from a portal like this, stop and verify it through our internal IT channel before you download anything.