Patchwork Hackers Target Chinese Universities and Research Institutions Using EyeShell Backdoor
Date: July 31, 2023
Category: Cyber Espionage / Malware
A recent campaign has revealed that the hacking group known as Patchwork is actively targeting universities and research organizations in China. According to the KnownSec 404 Team, these attacks leverage a backdoor named EyeShell. Also referred to as Operation Hangover or Zinc Emerson, Patchwork is believed to operate on behalf of India and has been active since at least December 2015. Their attacks primarily focus on Pakistan and China, employing custom malware such as BADNEWS, typically via spear-phishing and watering hole techniques. This group exhibits tactical similarities with other Indian-affiliated cyber-espionage collectives, like SideWinder and the DoNot Team. In a related development, Meta announced in May that it had suspended 50 accounts on Facebook and Instagram connected to Patchwork, which exploited rogue messaging apps.