<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf" -->

---
title: Pakistan&#x27;s Transparent Tribe Refreshes Tools for Afghan...
description: Pakistani state-linked threat actor Transparent Tribe (APT 36) has refreshed its malware toolkit with new backdoors named Patchcord and Sheetcord, alongside a...
canonical: https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Pakistan&#x27;s Transparent Tribe Refreshes Tools for Afghan Attacks | daily.dev
og:description: Pakistani state-linked threat actor Transparent Tribe (APT 36) has refreshed its malware toolkit with new backdoors named Patchcord and Sheetcord, alongside a...
og:url: https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf
og:image: https://api.daily.dev/og/posts/IeiZ3JtNF.png
og:image:alt: Pakistan&#x27;s Transparent Tribe Refreshes Tools for Afghan Attacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Pakistan's Transparent Tribe Refreshes Tools for Afghan Attacks

**[Dark Reading](https://daily.dev/sources/dr)** · 6 min read · 0 upvotes · 0 comments

## Summary

Pakistani state-linked threat actor Transparent Tribe (APT 36) has refreshed its malware toolkit with new backdoors named Patchcord and Sheetcord, alongside a RAT called Sheetcreep, to spy on high-value targets in Afghanistan and India. Patchcord, a C++ implant, favors in-memory execution and anti-analysis checks but relies on an old, easily detected persistence trick of hijacking desktop shortcuts. Sheetcord, written in Go, instead registers as a Windows startup process and hides C2 traffic via Google Sheets. A third framework, HackerAI, appears to be AI-generated malware using GitHub Gist for C2. The campaign, active since at least last December and intensifying in May, has successfully compromised an Afghan telecom subsidiary and an IT officer at Afghan Telecom, while attacks against better-defended Indian government agencies like the Ministries of Defense and Foreign Affairs have so far failed.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cyberattacks-data-breaches/pakistan-transparent-tribe-afghan-cyberattacks>

## Questions this post answers

### What is the Patchcord malware used by Transparent Tribe (APT 36)?

Patchcord is a newly documented C++ backdoor used by the Pakistani state-linked threat actor Transparent Tribe, also known as APT 36. It supports host fingerprinting, process enumeration, and in-memory arbitrary code execution, plus anti-sandbox checks added in a March variant. Its persistence mechanism hijacks victims' desktop shortcuts to run silently alongside the intended browser, an old technique that most endpoint products readily detect.

_Security teams tracking APT malware trends can follow emerging threat research on daily.dev._

### How is Transparent Tribe using Google Sheets and GitHub Gist for command and control?

Transparent Tribe's Go-based Sheetcord malware conceals its command-and-control traffic by routing it through Google Sheets, while a separate framework called HackerAI, believed to be built with AI coding assistance, uses GitHub Gist for C2. Sheetcord also registers itself as a Windows startup process rather than hijacking shortcuts like its sibling malware, Patchcord.

_Defenders investigating abuse of legitimate cloud services for C2 can stay current via daily.dev._

### Why has Transparent Tribe succeeded against Afghan targets but failed against Indian government agencies?

Transparent Tribe has confirmed infections at an Afghan telecom subsidiary and an IT officer at Afghan Telecom's Khost branch, but no confirmed compromises against Indian ministries of Defense, Foreign Affairs, the National Informatics Centre, or the Indian Air Force despite tailored phishing lures. Acronis researcher Subhajeet Singha attributes this to Afghanistan's weaker cybersecurity maturity versus India's stronger defenses, including CERT-In broadly blocking the group's well-known infrastructure.

_Teams benchmarking regional cyber defense maturity can track APT campaign outcomes on daily.dev._

## Similar posts on daily.dev

- [Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia](https://daily.dev/posts/transparent-tribe-launches-new-rat-attacks-against-indian-government-and-academia-czwn6hdlu) · The Hacker News · 2 upvotes · 0 comments
- [APT Attacks Target Indian Government Using SHEETCREEP, FIREPOWER, and MAILCREEP \| Part 2](https://daily.dev/posts/apt-attacks-target-indian-government-using-sheetcreep-firepower-and-mailcreep-part-2-vmtqh8kau) · Security Boulevard · 0 upvotes · 0 comments
- [APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign](https://daily.dev/posts/apt36-targets-indian-government-with-golang-based-deskrat-malware-campaign-0jaffzcrq) · The Hacker News · 1 upvotes · 0 comments
- [Nation-State Actor Embraces AI Malware Assembly Line](https://daily.dev/posts/nation-state-actor-embraces-ai-malware-assembly-line-u0sjs11xk) · Dark Reading · 1 upvotes · 0 comments
- [Iranian Hackers Launch 'SpearSpecter' Spy Operation on Defense & Government Targets](https://daily.dev/posts/iranian-hackers-launch-spearspecter-spy-operation-on-defense-government-targets-lbt7r1gbv) · The Hacker News · 1 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Pakistan's Transparent Tribe Refreshes Tools for Afghan Attacks","url":"https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf"},"datePublished":"2026-08-20T15:02:47.604Z","dateModified":"2026-09-13T21:10:24.797Z","description":"Pakistani state-linked threat actor Transparent Tribe (APT 36) has refreshed its malware toolkit with new backdoors named Patchcord and Sheetcord, alongside a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/668d7d4295e7ce5a2c7128d626d00b1a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/668d7d4295e7ce5a2c7128d626d00b1a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,phishing","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"Pakistan's Transparent Tribe Refreshes Tools for Afghan Attacks"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/pakistan-s-transparent-tribe-refreshes-tools-for-afghan-attacks-ieiz3jtnf#faq","mainEntity":[{"@type":"Question","name":"What is the Patchcord malware used by Transparent Tribe (APT 36)?","acceptedAnswer":{"@type":"Answer","text":"Patchcord is a newly documented C++ backdoor used by the Pakistani state-linked threat actor Transparent Tribe, also known as APT 36. It supports host fingerprinting, process enumeration, and in-memory arbitrary code execution, plus anti-sandbox checks added in a March variant. Its persistence mechanism hijacks victims' desktop shortcuts to run silently alongside the intended browser, an old technique that most endpoint products readily detect. Security teams tracking APT malware trends can follow emerging threat research on daily.dev."}},{"@type":"Question","name":"How is Transparent Tribe using Google Sheets and GitHub Gist for command and control?","acceptedAnswer":{"@type":"Answer","text":"Transparent Tribe's Go-based Sheetcord malware conceals its command-and-control traffic by routing it through Google Sheets, while a separate framework called HackerAI, believed to be built with AI coding assistance, uses GitHub Gist for C2. Sheetcord also registers itself as a Windows startup process rather than hijacking shortcuts like its sibling malware, Patchcord. Defenders investigating abuse of legitimate cloud services for C2 can stay current via daily.dev."}},{"@type":"Question","name":"Why has Transparent Tribe succeeded against Afghan targets but failed against Indian government agencies?","acceptedAnswer":{"@type":"Answer","text":"Transparent Tribe has confirmed infections at an Afghan telecom subsidiary and an IT officer at Afghan Telecom's Khost branch, but no confirmed compromises against Indian ministries of Defense, Foreign Affairs, the National Informatics Centre, or the Indian Air Force despite tailored phishing lures. Acronis researcher Subhajeet Singha attributes this to Afghanistan's weaker cybersecurity maturity versus India's stronger defenses, including CERT-In broadly blocking the group's well-known infrastructure. Teams benchmarking regional cyber defense maturity can track APT campaign outcomes on daily.dev."}}]}
```

