The Pakistan-based cyber espionage group known as Transparent Tribe, or APT 36, has upgraded its digital toolset to launch targeted cyberattacks against major institutions in Afghanistan. Cybersecurity analysts have tracked this active group for years due to its persistent monitoring of neighboring nations. The latest intelligence reports reveal that the hackers are now using updated custom malware to secretly penetrate and monitor foreign network infrastructures.

This newly refreshed digital arsenal features two sophisticated backdoors named Patchcord and Sheetcord, designed specifically for stealthy espionage operations. These tools allow the attackers to control infected systems remotely while evading standard security detection software. The primary trick used by this malware involves hijacking standard desktop shortcuts on target computers to maintain long-term, hidden access.

The primary targets of this latest campaign in Afghanistan include high-value government agencies and major national telecommunications networks. However, security researchers noted that the group is also targeting smaller entities, including a local business and individual targets. The hackers use deceptive emails that disguisedly mimic network management and logistics tools used by prominent Afghan telecom providers.

To trick victims into installing the malicious payloads, the group relies heavily on tailored social engineering and deceptive phishing tactics. Victims are sent trick files that appear as official documents but actually execute hidden background installation commands. By setting up fake internet domains that mimic real institutions, the group successfully tricks users into trusting these malicious connections.

While focusing heavily on Afghan institutions, the threat actor has simultaneously attempted to breach strategic targets across India as well. The group created phishing traps disguised as energy conservation tools and government benefit resources intended for Indian officials. Despite these efforts, cybersecurity monitoring shows that the group’s attacks have faced stronger defensive roadblocks when attempting to compromise Indian networks.

Cybersecurity firm Acronis observed that this campaign picked up significant momentum in May and remains an active threat across the region. The group’s primary objective remains intelligence gathering and sensitive data exfiltration rather than immediate, destructive system disruption. By continuously refreshing its custom code, Transparent Tribe ensures its espionage tools stay ahead of standard cybersecurity filters.

The group’s ability to seamlessly target multiple operating systems shows how its technical capabilities have evolved over time. Beyond standard Windows environments, the threat actor has adapted its code to target mobile platforms and custom operating systems. Security experts warn that these frequent updates make early detection and network defense much harder for affected organizations.

Digital security teams urge high-value targets across the region to strengthen their email filtering and endpoint monitoring systems immediately. Organizations are advised to educate staff on identifying suspicious desktop shortcuts and misleading file attachments. As state-aligned cyber threats continue to refine their tactics, proactive surveillance remains essential to protecting sensitive networks.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news