Malware

Patchwork Hackers Upgraded Their Arsenal With Advanced PGoShell

Advanced Threat Intelligence Team, Knownsec 404 has recently discovered a potential Bhutan-targeted attack by the Patchwork group that has employed an advanced Go backdoor and the Brute Ratel C4 red team tool for the first time.

The vector of the attack is an illusionary PDF link file that downloads decoy files as well as payloads.

This shows how Patchwork has updated its arsenal significantly to address technological progress made over the last couple of years, and this evolution upgraded its arsenal with the advanced PGoShell.

Patchwork Hackers Upgraded Their Arsenal

Since 2014, this APT group has been functioning mainly against government, defense, diplomatic, and research organizations in East and South Asia. More than ten trojans and loading methods have been observed so far.

Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo

They also use deceptive LNK files for the attack. It downloads a decoy PDF targeting Bhutan-related organizations, retrieves the following two payloads from a domain impersonating Beijing TV, and creates scheduled tasks:-

  • edputil.dll
  • Winver.exe
Chains of attack (Source – Medium)

The Themida-packed edputil.dll is the loader for Brute Ratel C4 that uses anti-debugging techniques as well as custom API calling methods.

.themida section within the segment of edputil.dll (Source – Medium)

The final payload, Brute Ratel C4, loads into chakra.dll after performing time-based checks.

This red team framework, which is an alternative to Cobalt Strike, has features such as file management, port scanning, and screen capture that show how sophisticated the attack was and how the threat actor’s tactics are changing.

The Go-Based malware, codenamed PGoShell by the patchwork APT has grown a lot and now incorporates various features including remote shell, screen capture, and payload execution.

RC4 encryption is used as well as base64 encoding for data obfuscation.

Extensive information about the host is gathered by this malware such as IP geolocation through ip-api.com whereas HKCU\Software\Microsoft\WinTemp is used for persistence.

In one recent attack on Bhutan-related entities, Patchwork employed Brute Ratel C4, it’s a red team framework that costs $3000 and utilizes pure in-memory loading, anti-debugging, unhooking techniques, etc to bypass detection.

Brute Ratel C4 cost (Source – Medium)

The LNK file was misleadingly named so that it appeared like PDF information concerning the Adaptation Fund Board project.

With this adoption of Brute Ratel C4 and upgrading PGoShell, Patchwork seems to indicate an increasingly fast-changing modus operandi with regard to cyber operations, consequently further making their past achievements possible and future threats likely.

IoCs

C2:-

  • Beijingtv[.]org
  • Cartmizer[.]info
  • longwang.b-cdn[.]net

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago