From Open Directories to AI-Coded Malware: How a Pakistan-Nexus Threat Actor Leaked Their Entire Arsenal Targeting Afghan Telecom and South Asian Critical Infrastructure - Cybersecurity Conference

From Open Directories to AI-Coded Malware: How a Pakistan-Nexus Threat Actor Leaked Their Entire Arsenal Targeting Afghan Telecom and South Asian Critical Infrastructure

Title: In the Driver’s Seat: How I Watched a Pakistan-Nexus APT Build, Deploy, and Leak Their Entire Arsenal

What happens when a threat actor targeting Afghan telecom providers and Indian defence organizations accidentally leaves their entire working directory exposed to the internet? You get a front-row seat to their toolkit, their victim data, their staged campaigns, their exploit POCs and ultimately, their novel AI-coded malware and APT’s geolocation data.

In early 2026, Acronis TRU discovered a suspicious Inno Setup installer impersonating Afghan Telecom on a public sandbox What began as routine malware triage quickly escalated into a months-long investigation that uncovered three previously undocumented implant families, 16 rotating domains impersonating Afghan and Indian government entities, and a trail of operational security failures that gave us unprecedented visibility into a Pakistan-nexus threat actor’s operations.

The first implant, PATCHCORD, a custom C/C++ backdoor, led us to a live command-and-control server that was still actively responding during our research. Shodan reconnaissance revealed something the operator clearly never intended us to find: a Python SimpleHTTPServer running on port 4443 with a full directory listing of their home directory. Campaign files, staged spear-phishing archives, Metasploit, GateSentinel, SuperShell C2, exploit tooling for CVE-2024-6387, credential brute-forcing wordlists, and what appeared to be exfiltrated victim data including WhatsApp Web sessions, iOS call history records, router configuration backups, and power plant operational telemetry from two facilities, all sitting in plain view, indexed by Shodan for anyone to find.

But the real surprise came when we pulled on the infrastructure thread further. Historical SSL certificate analysis on the same server revealed a domain impersonating India’s Controller General of Defence Accounts dating back to September 2025, which was being used to deliver a third implant we have named HACKERAI C2 Agent. This Go-based implant, which uses GitHub Gists for its command-and-control communication, turned out to be vibecoded: AI-generated code comments were left intact throughout the binary, a string “obfuscation” routine applied XOR with key 0xAB twice effectively cancelling itself out, leftover test code reversed the string “test” for no apparent reason, and the developer had hardcoded a GitHub Personal Access Token directly into the binary’s .rdata section. This was the third time across three implants that the operator had hardcoded cloud credentials into their malware, having previously embedded a full Google Cloud service account with RSA private key in SHEETCORD, a Go-based implant abusing Google Sheets for C2 that we discovered being actively served through a domain impersonating India’s National Informatics Centre.

Across the three implants, one constant remained: browser shortcut hijacking. Every single implant, regardless of language or C2 channel, implemented the same persistence technique of rewriting desktop and taskbar shortcuts for web browsers to silently proxy-launch the malware on every browser open while preserving the original icon and appearance. Three languages, three cloud platforms, one signature technique.

This talk will take the audience through the full investigation, from the initial Inno Setup installer to reverse engineering three implant families, probing a live C2 server, exploiting an exposed open directory, discovering vibe-coded AI malware, and tracing the operator’s infrastructure across VirusTotal, Shodan, Validin, and FOFA, all the way to connections with the APT36 ecosystem and an unexpected overlap with the SilverFox/ValleyRAT cluster through shared SuperShell infrastructure. We will also discuss the emerging trend of AI-assisted malware development and what forensic indicators defenders should look for when threat actors start vibecoding their implants.

Topics covered:

  • Reverse engineering custom C/C++ and Go implants targeting South Asian critical infrastructure
  • Exploiting threat actor OPSEC failures: open directories, hardcoded credentials, and exposed staging servers
  • Cloud C2 abuse across three platforms: custom HTTP, Google Sheets, and GitHub Gists
  • AI-assisted malware development in the wild and its forensic fingerprints
  • Browser shortcut hijacking as a cross-implant signature technique
  • Infrastructure hunting and pivoting across passive DNS, certificate transparency, and favicon hashing.
  • A sneak-peek into operator behind APT36’s geolocation.
  • Attribution challenges at the intersection of APT36 and Chinese-origin tooling

Subhajeet Singha – Acronis

Subhajeet works as a senior threat researcher at Acronis, where he tracks APTs and researchers on various interesting TTPs, Subhajeet has uncovered multiple novel APTs as well as implants and loves reverse engineering & is an amateur MMA Enthusiast.