NEW: Group Profiler — instant APT intel lookup. Try it →

Patchwork

G0040 Espionage MITRE ATT&CK →

Also known as: Hangover Group · Dropping Elephant · Chinastrats · MONSOON · Operation Hangover

Overview

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.

Naming & attribution

Patchwork is tracked under 6 names across the industry. It uses 41 documented ATT&CK techniques — more than 76% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Hangover GroupLevene, B. et al.
Dropping ElephantHamada, J.
ChinastratsKaspersky Lab's Global Research & Analysis Team
MONSOONSettle, A., et al
Operation HangoverSettle, A., et al
PatchworkCymmetria

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1587.002 Code Signing Certificates — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Sidewinder India — 20 shared techniques (39% overlap)
  • BRONZE BUTLER China — 20 shared techniques (33% overlap)
  • Cobalt Group — 18 shared techniques (32% overlap)
  • APT3 China — 19 shared techniques (29% overlap)
  • MuddyWater Iran — 24 shared techniques (28% overlap)
  • Silence — 15 shared techniques (28% overlap)

Malware families with current indicators

One family attributed to Patchwork, carrying 5 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • BadNews 5 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Diplomacy · Finance · Government · Military · Private sector · Security Service

Regions

Bangladesh · Germany · Pakistan · Sri Lanka

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 6 attributed custom malware families

TTPs — 41 techniques across 13 tactics

Reconnaissance

Resource Development

Initial Access

Execution

Persistence

Privilege Escalation

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Tools & malware (8)

NDiskMonitor · QuasarRAT · BackConfig · TINYTYPHON · AutoIt backdoor · PowerSploit · BADNEWS · Unknown Logger

Reporting (3)