Published Thursday, August 13, 2026 at 10:40 AM PT

BLUF: Acronis Threat Research Unit identified an ongoing cyber-espionage campaign named Patchcord targeting Afghan telecommunications providers and critical infrastructure across South Asia. Attribution, TTPs, and scope remain incomplete; monitoring for updated reporting.
DETAILS:
- Campaign name: Patchcord (newly exposed by Acronis Threat Research Unit)
- Primary target: Afghan telecommunications providers and associated critical infrastructure
- Geographic scope: South Asia, with Afghanistan confirmed as primary focus
- Status: Ongoing β campaign is active, not concluded
- Source assessment: Acronis reporting is preliminary; full threat report appears truncated in available material; additional technical details not yet surfaced
IMPACT:
- Directly affected: Afghan telecom operators and their supporting critical infrastructure (power, water, emergency services connected via telecom)
- Regional risk: Other South Asian telecom operators should assume heightened targeting risk from the same actor(s)
- Scope: Unconfirmed β campaign may extend beyond Afghanistan; Patchcord’s full target list unknown
- Confidence level: LOW β insufficient published details to assess impact scale, dwell time, or data exfiltration scope
RECOMMENDED ACTIONS:
- Afghan telecom CSOs: assume breach posture; audit network logs for lateral movement and C2 communication dating back 6+ months
- Regional telecom operators: increase monitoring for similar TTPs; correlate IOCs when Acronis publishes full advisory
- US/allied ISACs: await full Acronis report; request TLP:WHITE technical indicators for defensive deployment
- Await Acronis Threat Research Unit full publication for actor attribution, malware families, and exploitation vectors
SOURCES:
- Acronis Threat Research Unit (reporting date and full URL not provided in available material β flagged as incomplete)
- Related context: Pattern aligns with stated nation-state interest in telecom/infrastructure targeting (2024 Charter Communications compromise, Iranian PLC campaigns, Russian IP-camera campaigns noted in security literature)
STATUS: This alert reflects fragmentary reporting. Full technical advisory may materially change assessment when published.
Recent high-severity events at publish time:

