PATCHCORD, a newly discovered backdoor, has been identified as a key component in an espionage campaign targeting Afghan telecom providers and South Asian critical infrastructure. The campaign, suspected to be carried out by APT36, utilizes fake VPN installers and management tools that mimic legitimate software to gain initial access. Notably, the attackers have leveraged Google Sheets as a command and control (C2) channel, adding a layer of stealth to their operations1. The use of Google Sheets in this manner highlights the evolving tactics of state-aligned threat actors, who are increasingly incorporating legitimate services into their toolsets. This shift in tactics necessitates a reevaluation of the threat model, as the motivations and goals of these actors differ significantly from those of traditional cybercriminals. The incorporation of Google services in PATCHCORD's C2 infrastructure underscores the need for practitioners to reassess their defenses against state-sponsored threats.