Description

Patchwork, a hacking group believed to be operating on behalf of India, is carrying out cyber-espionage against China and Pakistan. Patchwork( also known as Operation Hangover and Zinc Emerson) has been active since December 2015 and uses custom implants like BADNEWS through spear-phishing and watering hole attacks. In the recent campaign, a group is using a backdoor named EyeShell against universities and research organisations in China and Meta after the activities of Patchwork disclosed 50 Facebook and Instagram accounts operated by the group. During the analysis, researchers found a threat utilising these accounts to exploit rogue messaging apps on the Google Play Store to collect data from victims in several countries, including India, Pakistan, Bangladesh, Sri Lanka, Tibet, and China. Additionally, Patchwork used fictitious personas to deceive users into clicking on malicious links and downloading their apps, gaining access to user data through legitimate app permissions. Furthermore, the group found using an EyeShell, detected alongside BADNEWS, is a.NET-based modular backdoor capable of executing various commands, including file enumeration, downloading and uploading files, executing specified files, deleting files, and capturing screenshots. Additionally, a group was found operating under the name ModifiedElephant, where it carried out surveillance and planting of "incriminating digital evidence" operations on human rights activists, academics, and lawyers in India involved in the 2018 Bhima Koregaon violence in Maharashtra.