logo

Patchwork APT Group Unleashes Nexe Backdoor: A New Era in Cyber Espionage Tactics

ID: dc9afe35-38b8-59e3-8bc2-938b5d1e9220

STIX ID: report--dc9afe35-38b8-59e3-8bc2-938b5d1e9220

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2024-09-27

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Cyble Research and Intelligence Labs (CRIL) and other analysts have identified an active July 2024 Patchwork APT campaign that uses malicious LNK files to trigger PowerShell downloads of a benign-looking PDF and a malicious DLL. The DLL is executed via WerFaultSecure.exe DLL sideloading, decrypts and runs shellcode that patches AMSI/ETW to evade detection, collects system/user data (hashed and encrypted with SHA256 and Salsa20), maintains persistence via a scheduled 'EdgeUpdate' task, and exfiltrates data to a hardcoded C2 domain (iceandfire.xyz).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.