Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor

Share:

Threat actors associated with the hacking crew known as Patchwork have been spotted targeting universities and research organizations in China as part of a recently observed campaign.

The activity, according to KnownSec 404 Team, entailed the use of a backdoor codenamed EyeShell.

Patchwork, also known by the names Operation Hangover and Zinc Emerson, is suspected to be a threat group that operates on behalf of India. Active since at least December 2015, attack chains mounted by the outfit have a narrow focus and tend to single out Pakistan and China with custom implants such as BADNEWS via spear-phishing and watering hole attacks.

The adversarial collective has been found to share tactical overlaps with other cyber-espionage groups with an Indian connection, including SideWinder and the DoNot Team.

Earlier this May, Meta disclosed that it took down 50 accounts on Facebook and Instagram operated by Patchwork, which took advantage of rogue messaging apps uploaded to the Google Play Store to collect data from victims in Pakistan, India, Bangladesh, Sri Lanka, Tibet, and China.

Patchwork relied on a range of elaborate fictitious personas to socially engineer people into clicking on malicious links and downloading malicious apps, the social media giant said.

These apps contained relatively basic malicious functionality with the access to user data solely reliant on legitimate app permissions granted by the end user. Notably, Patchwork created a fake review website for chat apps where they listed the top five communication apps, putting their own, attacker-controlled app at the top of the list.

Some of its activities have also been reported under the name ModifiedElephant, according to Secureworks, referring to a set of attacks against human rights activists, academics, and lawyers across India to conduct long-term surveillance and plant incriminating digital evidence in connection with the 2018 Bhima Koregaon violence in the state of Maharashtra.

EyeShell, detected alongside BADNEWS, is a a .NET-based modular backdoor that comes with capabilities to establish contact with a remote command-and-control (C2) server and execute commands to enumerate files and directories, downloading and uploading files to and from the host, execute a specified file, delete files, and capture screenshots.

The findings come as the cybersecurity company also detailed another wave of phishing attacks orchestrated by a group called Bitter aimed at aerospace, military, large enterprises, national government affairs, and universities in the country with a new backdoor known as ORPCBackdoor.

The South Asian threat actor was previously detected targeting the nuclear energy industry in China with malware downloaders delivered via CHM and Microsoft Excel Files that are designed to create persistence and retrieve further payloads.

 

(c) Thin

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:31 pm, Jul 8, 2025
weather icon 18°C
L: 17° | H: 19°
overcast clouds
Humidity: 54 %
Pressure: 1019 mb
Wind: 3 mph N
Wind Gust: 6 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 85%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
17° | 19°°C 0.18 mm 18% 7 mph 57 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 18°°C 0 mm 0% 3 mph 52 % 1019 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 16°°C 0 mm 0% 3 mph 51 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 56 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,725.35
0.74%
Ethereum(ETH)
€2,221.05
2.94%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.96
1.64%
Solana(SOL)
€128.24
1.38%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.145195
2.22%
Shiba Inu(SHIB)
€0.000010
2.45%
Pepe(PEPE)
€0.000009
3.52%
Scroll to Top