APT36-Linked HACKERAI Implant Shows Signs of LLM-Assisted Malware Development
Brief
The activity uses three previously undocumented malware families PATCHCORD, SHEETCORD, and HACKERAI C2 Agent and shows possible links to APT36 , also known as Transparent Tribe.
Researchers assess the attribution with moderate confidence. The assessment is based on the group’s targeting patterns, shared infrastructure, malware similarities, and tools found on an exposed staging server.
The campaign primarily targets telecom, government, defense, and energy organizations in Afghanistan and India.
Telecom companies are high-value targets because attackers can potentially access communications systems, subscriber data, and sensitive government-related information.
The campaign shows that the operators are expanding beyond traditional government and military espionage targets.
