Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor

Teilen:

Threat actors associated with the hacking crew known as Patchwork have been spotted targeting universities and research organizations in China as part of a recently observed campaign.

The activity, according to KnownSec 404 Team, entailed the use of a backdoor codenamed EyeShell.

Patchwork, also known by the names Operation Hangover and Zinc Emerson, is suspected to be a threat group that operates on behalf of India. Active since at least December 2015, attack chains mounted by the outfit have a narrow focus and tend to single out Pakistan and China with custom implants such as BADNEWS via spear-phishing and watering hole attacks.

The adversarial collective has been found to share tactical overlaps with other cyber-espionage groups with an Indian connection, including SideWinder and the DoNot Team.

Earlier this May, Meta disclosed that it took down 50 accounts on Facebook and Instagram operated by Patchwork, which took advantage of rogue messaging apps uploaded to the Google Play Store to collect data from victims in Pakistan, India, Bangladesh, Sri Lanka, Tibet, and China.

Patchwork relied on a range of elaborate fictitious personas to socially engineer people into clicking on malicious links and downloading malicious apps, the social media giant said.

These apps contained relatively basic malicious functionality with the access to user data solely reliant on legitimate app permissions granted by the end user. Notably, Patchwork created a fake review website for chat apps where they listed the top five communication apps, putting their own, attacker-controlled app at the top of the list.

Some of its activities have also been reported under the name ModifiedElephant, according to Secureworks, referring to a set of attacks against human rights activists, academics, and lawyers across India to conduct long-term surveillance and plant incriminating digital evidence in connection with the 2018 Bhima Koregaon violence in the state of Maharashtra.

EyeShell, detected alongside BADNEWS, is a a .NET-based modular backdoor that comes with capabilities to establish contact with a remote command-and-control (C2) server and execute commands to enumerate files and directories, downloading and uploading files to and from the host, execute a specified file, delete files, and capture screenshots.

The findings come as the cybersecurity company also detailed another wave of phishing attacks orchestrated by a group called Bitter aimed at aerospace, military, large enterprises, national government affairs, and universities in the country with a new backdoor known as ORPCBackdoor.

The South Asian threat actor was previously detected targeting the nuclear energy industry in China with malware downloaders delivered via CHM and Microsoft Excel Files that are designed to create persistence and retrieve further payloads.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:13 am, Juli 2, 2025
Wetter-Symbol 21°C
L: 20° | H: 22°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 76 %
Druck: 1014 mb
Wind: 7 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 33%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 22°°C 0.38 mm 38% 11 mph 79 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 13 mph 81 % 1012 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 6 mph 77 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
18° | 19°°C 0.2 mm 20% 5 mph 79 % 1016 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0.2 mm 20% 6 mph 71 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0.38 mm 38% 4 mph 69 % 1018 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
23° | 23°°C 0.35 mm 35% 6 mph 41 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
23° | 23°°C 0.01 mm 1% 11 mph 28 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 34 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 37 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,522.80
-1.36%
Ethereum(ETH)
€2,037.93
-3.27%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.84
-2.89%
Solana(SOL)
€124.41
-5.21%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.133618
-4.51%
Shiba Inu(SHIB)
€0.000009
-2.12%
Pepe(PEPE)
€0.000008
-5.16%
Nach oben scrollen