India-linked Patchwork APT targets Chinese research orgs with EyeShell backdoor

India-linked Patchwork APT targets Chinese research orgs with EyeShell backdoor

An India-based threat actor has been observed targeting universities and research organizations in China with a new backdoor called “EyeShell.” The findings come from researchers from Knownsec 404 Advanced Threat Intelligence Team, who have been tracking the Patchwork APT for the last two years.

Patchwork aka Dropping Elephant, Chinastrats, Monsoon, Sarit, Quilted Tiger, APT-C-09, and Zinc Emerson, is an Indian cyber-espionage group that has been active since December 2015. The threat actor targets high-profile entities like foreign embassies and diplomatic offices in Pakistan, Sri Lanka, Uruguay, Bangladesh, Taiwan, Australia, and the US while also focusing on China.

In the most recent campaign, the group has been observed deploying the EyeShell backdoor alongside the Badnews custom implant on the compromised systems.

EyeShell is a .NET-based modular backdoor that is able to establish contact with a remote command-and-control (C2) server and execute commands to enumerate files and directories, download/upload files to and from the host, execute a specified file, delete files, and capture screenshots.

Earlier this year, Facebook parent Meta disrupted a cyber-espionage operation linked to Patchwork. The company removed about 50 accounts on Facebook and Instagram linked to another India-based threat actor, Patchwork APT. The group targeted people in Pakistan, India, Bangladesh, Sri Lanka, the Tibet region, and China, including military personnel, activists, and minority groups.


Back to the list

Latest Posts

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

LOSTKEYS is designed to steal sensitive files, harvest system information, and exfiltrate details about running processes.
8 May 2025
Russia-aligned operation manipulates audio and images to impersonate experts

Russia-aligned operation manipulates audio and images to impersonate experts

The operation primarily focused on undermining NATO support for Ukraine and spreading false narratives to disrupt domestic politics in EU member states.
7 May 2025
Global network of DDoS-for-hire services dismantled in international police op

Global network of DDoS-for-hire services dismantled in international police op

The suspects are believed to have administered six now-defunct websites, which operated as stresser or booter services.
7 May 2025