PATCHCORD is a previously undocumented C/C++ backdoor delivered via fake VPN installers and telecom management tools. It establishes persistence by hijacking browser shortcuts, communicates with a C2 server, and can execute shellcode and arbitrary commands. It has been used since at least March 2026, including against India's energy sector with anti-analysis techniques.