NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Patchwork

Patchwork

G0040 Espionage MITRE ATT&CK →

Also known as: Hangover Group · Dropping Elephant · Chinastrats · MONSOON · Operation Hangover

Overview

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.

Targets

Diplomacy · Finance · Government · Military · Private sector · Security Service

Regions

Bangladesh · Germany · Pakistan · Sri Lanka

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 6 attributed custom malware families

TTPs — 41 techniques across 13 tactics

Reconnaissance

Resource Development

Initial Access

Execution

Persistence

Privilege Escalation

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Tools & malware (8)

NDiskMonitor · QuasarRAT · BackConfig · TINYTYPHON · AutoIt backdoor · PowerSploit · BADNEWS · Unknown Logger

Reporting (3)