Agonist / Blog Platform How it works Blog
EN TR
Threat Intel

Patchcord: A Quiet Espionage Campaign Aimed at South Asian Telecom and Infrastructure

Acronis researchers have uncovered a long-running espionage operation against Afghan telecom providers and regional critical infrastructure — a reminder that phone networks are OT targets too.

August 14, 2026 5 min read OT Threat Intelligence
EN TR

Acronis’ Threat Research Unit published findings this week on a campaign it calls Patchcord, targeting telecommunications providers and critical infrastructure operators in Afghanistan and the wider South Asia region. The public details are still thin, which is typical for this kind of research at the point of first disclosure, but the target list tells you most of what you need to know. Telecom backbones sit exactly where state-aligned intelligence collection wants to be: high volumes of communications metadata, cross-border links, and — increasingly — the physical infrastructure that keeps all of it running.

That last part is the piece people outside OT tend to miss. Telecom isn’t usually filed under industrial control systems in most people’s mental model, but the physical layer of a telecom network runs on the same kind of equipment you’d find in a water utility or a power substation. Transmission huts have generator sets and battery banks with their own controllers. Exchange buildings have environmental control systems keeping switching equipment from cooking itself in summer heat. Cell towers in areas without reliable grid power often run on remotely monitored diesel gensets. None of this is exotic PLC territory, but it’s still OT, and it’s still frequently managed by the same IT staff who run the billing systems and the email servers.

Why This Isn’t Just an IT Story

An attacker who gets a foothold in a telecom operator’s corporate network is often only a few hops from the systems that keep towers powered, keep switching centers cool, and keep the network itself observable. In a country like Afghanistan, where telecom infrastructure also underpins mobile banking, government communications, and regional connectivity projects that several neighboring states have strategic interest in, a persistent espionage foothold has value that goes well beyond intercepted calls. It’s positioning. Long-dwell-time access into a telecom provider gives an operator visibility into who’s talking to whom, plus a launching pad into any downstream network the provider touches — including, potentially, the OT of other critical infrastructure sectors that lease fiber or colocate equipment.

Campaigns like this rarely look dramatic while they’re running. There’s no ransomware note, no defaced webpage, no obvious outage. The entire value proposition for the operator is staying invisible for as long as possible, which is exactly why these things tend to get discovered by threat intel teams doing pattern analysis across incidents rather than by the victim organization noticing something wrong. By the time a campaign gets a name and a public writeup, it’s usually been running for a while.

The absence of visible damage is not evidence of absence. It’s usually evidence the operation is working as intended.

For defenders in telecom and adjacent critical infrastructure, the practical takeaway isn’t about this specific campaign — it’s about the assumption that OT-adjacent systems inside a telecom environment are somehow lower priority than the core network. Facility management systems, generator controllers, and environmental monitoring platforms are frequently left on flat networks with shared credentials because nobody thinks of them as sensitive. They’re sensitive precisely because nobody’s watching them, which makes them ideal staging points for lateral movement once an initial foothold on the IT side is established.

The fix isn’t complicated, it’s just unglamorous: segment the OT-adjacent systems from the corporate network the same way you’d segment a control room from the business network in a manufacturing plant, monitor for lateral movement between the two, and stop treating remote access into facility systems as a lower-priority ticket than remote access into the core switching platform. Espionage campaigns like Patchcord succeed because that boundary usually doesn’t exist yet.

Source: https://industrialcyber.co/critical-infrastructure/acronis-exposes-patchcord-cyber-espionage-campaign-targeting-telecom-and-critical-infrastructure-in-south-asia/

ICSOT SecurityThreat Intelligence

More from the blog