logo

Nexe Backdoor: Patchwork APT's Evasive Tactics

ID: 86d312d8-4251-5529-ac88-df7eabdff1ba

STIX ID: report--86d312d8-4251-5529-ac88-df7eabdff1ba

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

Cyble Research and Intelligence Labs observed an active Patchwork APT campaign using malicious LNK files that invoke PowerShell to download a decoy PDF and a malicious DLL, perform DLL sideloading via WerFaultSecure.exe, decrypt and execute shellcode in memory, patch AMSI/ETW APIs to evade detection, and exfiltrate system identifiers to hardcoded C2 domains (e.g., iceandfire.xyz, scapematic.info). The report provides technical analysis, IOCs (hashes, URLs, domain), a YARA rule, MITRE ATT&CK mappings, and recommendations for email filtering, script restrictions, application whitelisting, and network monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.