APT36-linked malware cluster targets South Asia telecoms
What happened
Acronis identified a malware cluster targeting telecommunications providers and related infrastructure in South Asia and Afghanistan, linking the activity with moderate confidence to an APT actor. The cluster uses three previously undocumented implants and abuses legitimate cloud services (Google Sheets, GitHub Gists) for command-and-control, making normal URL-blocking ineffective. Watch whether indicators expand into regional supplier tooling or escalate to broader telco support channels
Why the category manager should care
Treat telco and MSP contracts as a first line of cyber defence; the supplier’s operational response capability materially affects buyer incident outcomes
Key facts
- Three new malware families identified (PATCHCORD, SHEETCORD, HACKERAI C2 Agent)
- Campaign targets telecom, government, defence and energy organisations
- Malware abuses Google Sheets and GitHub Gists for command-and-control