Patchwork is an India-based advanced persistent threat group also known as Dropping Elephant, APT-C-09, Quilted Tiger, Chinastrats, Monsoon, Hangover Group, Operation Hangover, and Zinc Emerson. Its targeting includes Pakistan and China, alongside countries in South Asia, Europe, North America, and East Asia. Its operations involve targeted compromise, remote access, and information theft. Patchwork uses spearphishing emails containing malicious attachments or links to exploit-bearing files for initial access. It embeds per-recipient tracking images in emails to identify recipients who open messages. Its post-compromise tooling includes publicly available software such as QuasarRAT, Meterpreter, and PowerSploit. The group has used reverse shells, JavaScript, and Windows scriptlets to execute code, download additional payloads, and interact with compromised systems. Patchwork establishes persistence through Windows scheduled tasks, including task-scheduling functionality in its file-stealing malware. It has attempted lateral movement using Remote Desktop Protocol and has extracted Chrome's browser credential database. Defense-evasion techniques include script obfuscation with Crypto Obfuscator and DLL sideloading through legitimate applications, including Oracle Java components in Monsoon activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 malware families attributed to this actor across reporting.
17 additional families tracked in Mallory.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
This malicious RTF file takes advantage of the vulnerability CVE-2015-1641. Upon successful exploitation, it drops a malware in the %appdata%\Microsoft directory.
The related attack vector is an XLSM file, created on August 8 and uploaded to VT on August 13, that leverages CVE-2017-11882 vulnerability to release MSBuild.exe to the %AppData% directory and then add registry Run key to stay persistent.
...has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158...
Patchwork... previously exploited CVE-2017-8570, CVE-2012-1856...
...exploited Microsoft vulnerabilities, including CVE-2014-4114...
6 more CVEs tied to this actor tracked in Mallory.
1,197 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an annotated actor associated with the detection technique.
Listed in the detection annotation metadata.
Listed only as an annotation associated with the detection.
Patchwork is listed in the detection's threat-actor annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.