Close Menu
    Facebook X (Twitter) Instagram
    Sunday, November 9
    Facebook X (Twitter) Instagram
    SecurNerd
    • Home
    • General News
    • Cyber Attacks
    • Threats
    • Vulnerabilities
    • Cybersecurity
    • Contact Us
    • More
      • About US
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
    SecurNerd
    Home»Cyber Crime»Patchwork Cyber Group Targets Chinese Academic and Research Institutions with EyeShell Backdoor
    Network security and privacy crime. Computer hacker working on laptop, programming bugs and viruses.
    Cyber Crime

    Patchwork Cyber Group Targets Chinese Academic and Research Institutions with EyeShell Backdoor

    securnerdBy securnerdJuly 31, 2023No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In a recent cyber espionage campaign, the threat actors, allegedly linked to the group known as Patchwork, are observed to be targeting Chinese universities and research institutions. KnownSec 404 Team has reported this activity, noting the deployment of a backdoor, codenamed EyeShell.

    Patchwork, also recognized as Operation Hangover and Zinc Emerson, is believed to be an Indian-backed cyber threat group. Active since at least December 2015, the group’s operations are usually narrowly focused, primarily targeting Pakistan and China with custom implants such as BADNEWS through spear-phishing and watering hole attacks.

    The group has been linked with cyber-espionage entities with an Indian connection, including SideWinder and the DoNot Team, based on overlapping tactics.

    Earlier in May, Meta identified and disabled 50 Patchwork-operated accounts on Facebook and Instagram. The group leveraged rogue messaging apps on the Google Play Store to harvest data from users in Pakistan, India, Bangladesh, Sri Lanka, Tibet, and China.

    “Patchwork deployed a series of sophisticated fake personas to socially engineer users into clicking on malicious links and downloading harmful apps,” Meta commented on the issue.

    EyeShell is a .NET-based modular backdoor that interacts with a remote command-and-control (C2) server. Its functionalities include executing commands to enumerate files and directories, downloading and uploading files, executing specified files, deleting files, and capturing screenshots.

    Patchwork also reportedly created a counterfeit review site for chat apps, deceptively promoting their own attacker-controlled app at the top of the list.

    Another alias linked with Patchwork’s activities is ModifiedElephant, according to Secureworks. The name corresponds to attacks against human rights activists, academics, and lawyers across India, intended for long-term surveillance and planting “incriminating digital evidence” in relation to the 2018 Bhima Koregaon violence in Maharashtra.

    In a parallel development, another round of phishing attacks has been identified, led by the group Bitter, targeting aerospace, military, large corporations, national government affairs, and universities in China, deploying a new backdoor named ORPCBackdoor.

    Bitter, a South Asian threat actor, has previously been observed to target the nuclear energy sector in China, delivering malware via CHM and Microsoft Excel Files, designed to establish persistence and download additional payloads.

    Found this news interesting? Follow us on Twitter  and Telegram to read more exclusive content we post.

    Post Views: 55
    Featured Trending
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMicrosoft Edge Deepens Dark Mode Experience with Enhanced Theme
    Next Article This AI Paper Deploys a Light-Weight Foundational Model in Outer Space for the First Time
    securnerd
    • Website
    • Facebook
    • X (Twitter)
    • Instagram

    We're your premier source for the latest in AI, cybersecurity, science, and technology. Dedicated to providing clear, thorough, and accurate information, our team brings you insights into the innovations that shape tomorrow. Let's navigate the future together."

    Related Posts

    AI July 22, 2024

    Complete HTML Handwritten Notes

    July 22, 2024
    AI July 21, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024
    Python June 23, 2024

    PyQt Mastery: From Beginner to Advanced

    June 23, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    Join the Community
    Recent Post

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024

    Top 7 Open-Source LLMs for 2024 and Their Uses

    July 18, 2024
    About Us
    About Us

    We're your premier source for the latest in AI, cybersecurity, science, and technology. Dedicated to providing clear, thorough, and accurate information, our team brings you insights into the innovations that shape tomorrow. Let's navigate the future together."

    Latest

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024
    Popular Post

    Independent Lab Validates Nubeva’s Innovative Ransomware Key Interception and Decryption Technology

    July 26, 202316 Views

    Vulnerabilities in WordPress Ninja Forms Plugin Expose User Data to Theft

    July 28, 202332 Views

    Hacking Group Cult of the Dead Cow Develops Veilid, an End-to-End Encryption System for Social Media and Messaging Apps

    August 3, 202356 Views

    Ukraine Enhances Wartime Efforts Through Advanced Cyber Intelligence Strategies

    August 10, 20235 Views

    Comfortable Pairs of Sneakers to Walk All Day

    September 6, 20231 Views

    How to Do the Superman Standing Exercise

    September 6, 20230 Views

    Tips to Ensure You Always Look Stylish

    September 6, 20231 Views

    A Mild, Sweet Fruit With a Fibrous Center

    September 6, 20230 Views

    For Good Results Must Be Make Good Plan

    September 6, 20230 Views

    Mistakes You Might Be Making With Your Watch

    September 6, 20231 Views
    Facebook X (Twitter) Instagram Pinterest
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.