Summary:
The Patchwork group, a sophisticated threat actor, has been observed conducting a series of targeted attacks against entities in China. The threat group is from India. Through comprehensive research and analysis, several threat advisories have been compiled, shedding light on Patchwork's tactics, techniques, and tools. This advisory will provide an overview of the identified threats, detailing their technical aspects and operational flow, thereby enabling organizations to enhance their defense and detection capabilities against Patchwork's activities. Patchwork's operations against entities in China involve the deployment of multiple malware variants and the use of sophisticated techniques to infiltrate and compromise targeted systems.[/subscribe_to_unlock_form]
Summary:
The Patchwork group, a sophisticated threat actor, has been observed conducting a series of targeted attacks against entities in China. The threat group is from India. Through comprehensive research and analysis, several threat advisories have been compiled, shedding light on Patchwork's tactics, techniques, and tools. This advisory will provide an overview of the identified threats, detailing their technical aspects and operational flow, thereby enabling organizations to enhance their defense and detection capabilities against Patchwork's activities. Patchwork's operations against entities in China involve the deployment of multiple malware variants and the use of sophisticated techniques to infiltrate and compromise targeted systems.[emaillocker id="1283"]
Patchwork employs the Ragnatela malware. This malware exploits the CVE-2017-11882 vulnerability found in RTF files to gain initial access to the targeted system. The attackers distribute malicious documents through spear phishing emails, likely containing malicious links. Upon execution, the malware exploits shellcode to create the Ragnatela malware in the victim’s system. This allows the attackers to establish persistence and collect system information. The malware also supports the execution of system commands, enabling the extraction of additional system details.
Patchwork introduces the Remcos remote access Trojan (RAT) to their arsenal. They send emails with attached malicious ZIP files, containing files with military-political names, to their targets. These emails likely serve as a delivery mechanism for the Remcos samples. Researchers have identified a compromised website, as a host for the malicious documents used in the attack. The communication with the Command and Control (C2) server occurs via the port 443. Patchwork employs Remcos for remote control capabilities, granting them access to compromised systems and enabling the exfiltration of sensitive data.
Then researcher reveals the discovery of a new backdoor named EYEShell associated with Patchwork. EYEShell can be divided into three modules: Initialization, Online, and Server Interaction. In the Initialization module, the backdoor creates a mutex and encrypts the data using the AES-128 algorithm. It then determines the C2 server and establishes communication. The Online module checks the availability of the server and collects information about the UUID, username, and OS version. This information is transferred to the server in a specific format. The Server Interaction module runs in a loop and supports several commands received from the C2 server, allowing Patchwork to maintain control over compromised systems.
After that Patchwork's focuses on the usage of Badnews malware and the incorporation of open source tools. The attackers leverage a .lnk file as a means of downloading Badnews in their attacks against China. By exploiting a double extension in the filename (e.g., pdf.lnk), they mask the true file type and deceive victims. Once executed, the .lnk file loads a decoy file and the Badnews sample from malicious URLs. Patchwork also utilizes open source tools such as SparkRAT, NorthStarC2, and EddieIvan01, which enhance their capabilities in various attack scenarios. They establish persistence through scheduled tasks and collect system information, potentially for further exploitation.
Finally, researchers uncover Patchwork's usage of a Badnews version and their implementation of a keyboard hook. The attackers send emails with malicious attachments, utilizing disguised file types with double extensions. Upon execution of the .lnk files, Patchwork loads decoy and Badnews samples from malicious URLs. The malware creates a mutex, possibly for synchronization or preventing multiple instances, and implements a keyboard hook to collect keyboard data. Collected data is saved to a .dat file in the %temp% directory. The attackers use legitimate services to obtain the victim's external IP address and cross-reference it with IP geolocation services to determine the country. Patchwork collects victim system information, encodes it (Base64), encrypts it (AES-CBC-128), and encodes it again (Base64) for transmission. Interactions with the C&C server involve the creation of multiple threads: one for transferring collected victim information, another for remote control, and a third for executing command-line commands.
In conclusion, Patchwork's targeted attacks against entities in China showcase their advanced capabilities and continuous evolution. Their usage of diverse malware variants, such as Ragnatela, Remcos, Badnews, and the newly discovered EYEShell, demonstrates their adaptability and persistence. By incorporating open source tools, employing sophisticated techniques like mutex creation and keyboard hooks, and exploiting vulnerabilities, Patchwork aims to maintain long-term access to compromised systems and gather sensitive information. To enhance their security posture, organizations are advised to implement robust threat detection mechanisms, promptly patch vulnerabilities, and educate users about phishing and social engineering techniques. Staying updated with threat intelligence and fostering collaboration with industry peers and cybersecurity professionals are essential for proactively countering Patchwork's evolving tactics and protecting against their targeted operations.
Threat Profile:

References:
The following reports contain further technical details:
https://www.anquanke.com/post/id/288891
https://cn-sec.com/archives/1754843.html
https://cn-sec.com/archives/1757937.html
[/emaillocker]