Patchwork is a cyber espionage threat actor widely assessed to originate from India. The group is also tracked as Dropping Elephant, Operation Hangover, Chinastrats, Monsoon, Quilted Tiger, APT-C-09, Patchwork APT, and Zinc Emerson. It has historically focused on regional strategic and political targets, with reporting linking its activity to victims in China and Pakistan as well as additional targets in South Asia and occasional broader international targeting. Patchwork commonly relies on spearphishing with malicious attachments for initial access. Post-compromise tradecraft includes downloading additional payloads from command-and-control infrastructure, use of PowerShell and Visual Basic or VBScript components for execution, and DLL side-loading to launch malicious code through legitimate executables. The group has also used reverse shells and commodity or publicly available tooling in support of operations. Observed Patchwork capabilities include host reconnaissance and victim profiling, such as collecting computer name, operating system version, architecture, username, privilege context, and available drives. It has searched local drives for files of interest and exfiltrated collected data. Credential access activity includes theft of browser-stored credentials, including extraction of Chrome login data. For persistence, Patchwork has used startup-folder mechanisms and scheduled-task-related components. Defense evasion and anti-forensics behaviors include Base64-encoded command-and-control traffic, deletion or replacement of files, and removal of Microsoft Office resiliency artifacts to reduce visible signs of malicious document execution. Patchwork is best characterized as an espionage-oriented intrusion set conducting targeted collection operations rather than financially motivated ransomware or extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 malware families attributed to this actor across reporting.
17 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
This malicious RTF file takes advantage of the vulnerability CVE-2015-1641. Upon successful exploitation, it drops a malware in the %appdata%\Microsoft directory.
The related attack vector is an XLSM file, created on August 8 and uploaded to VT on August 13, that leverages CVE-2017-11882 vulnerability to release MSBuild.exe to the %AppData% directory and then add registry Run key to stay persistent.
...has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158...
Patchwork... previously exploited CVE-2017-8570, CVE-2012-1856...
...exploited Microsoft vulnerabilities, including CVE-2014-4114...
5 more CVEs tied to this actor tracked in Mallory.
1,188 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage campaign using fake PDF/LNK lures on Windows and trojanized Android chat apps to surveil targets, steal files and messages, capture screenshots/keystrokes/audio, and maintain persistence across desktop and mobile devices.
Conducting espionage campaigns using malicious Windows shortcut files and trojanized Android chat applications to surveil targets and steal sensitive information from both desktop and mobile environments.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.