Patchcord APT: Custom Backdoor Campaign Targeting South Asian Critical Infrastructure
The Patchcord APT group has deployed a bespoke, custom-engineered backdoor (PE/ELF) targeting critical infrastructure, telecommunications, and government sectors across South Asia. The campaign utilizes a sophisticated C2 infrastructure to facilitate long-term intelligence gathering and surveillance of regional telecom traffic and government communications. Persistence is achieved through registry modifications, scheduled tasks, and service injection. Technical artifacts indicate the use of specialized lateral movement toolsets tailored for telecom network architectures and obfuscated data exfiltration methods. This operation poses a severe risk to national security and operational stability through the strategic exfiltration of sensitive government metadata and real-time traffic.