Patchwork
Also known as: Hangover Group · Dropping Elephant · Chinastrats · MONSOON · Operation Hangover
Overview
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.
Naming & attribution
Patchwork is tracked under 6 names across the industry. It uses 41 documented ATT&CK techniques — more than 76% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Hangover Group | Levene, B. et al. |
| Dropping Elephant | Hamada, J. |
| Chinastrats | Kaspersky Lab's Global Research & Analysis Team |
| MONSOON | Settle, A., et al |
| Operation Hangover | Settle, A., et al |
| Patchwork | Cymmetria |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1587.002Code Signing Certificates — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Sidewinder India — 20 shared techniques (39% overlap)
- BRONZE BUTLER China — 20 shared techniques (33% overlap)
- Cobalt Group — 18 shared techniques (32% overlap)
- APT3 China — 19 shared techniques (29% overlap)
- MuddyWater Iran — 24 shared techniques (28% overlap)
- Silence — 15 shared techniques (28% overlap)
Malware families with current indicators
One family attributed to Patchwork, carrying 5 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- BadNews 5 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Diplomacy · Finance · Government · Military · Private sector · Security Service
Regions
Bangladesh · Germany · Pakistan · Sri Lanka
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
- Custom malware/implant development — ATT&CK: 6 attributed custom malware families
TTPs — 41 techniques across 13 tactics
Reconnaissance
-
T1598.003Spearphishing Link
Resource Development
-
T1587.002Code Signing Certificates -
T1588.002Tool
Initial Access
-
T1189Drive-by Compromise -
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1203Exploitation for Client Execution -
T1204.001Malicious Link -
T1204.002Malicious File -
T1559.002Dynamic Data Exchange
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Privilege Escalation
-
T1548.002Bypass User Account Control
Stealth
-
T1027.001Binary Padding -
T1027.002Software Packing -
T1027.005Indicator Removal from Tools -
T1027.010Command Obfuscation -
T1036.005Match Legitimate Resource Name or Location -
T1055.012Process Hollowing -
T1070.004File Deletion -
T1197BITS Jobs -
T1574.001DLL
Defense Impairment
-
T1112Modify Registry -
T1553.002Code Signing
Credential Access
-
T1555.003Credentials from Web Browsers
Discovery
-
T1033System Owner/User Discovery -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1518.001Security Software Discovery -
T1680Local Storage Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol
Collection
-
T1005Data from Local System -
T1074.001Local Data Staging -
T1119Automated Collection -
T1560Archive Collected Data
Command and Control
-
T1102.001Dead Drop Resolver -
T1105Ingress Tool Transfer -
T1132.001Standard Encoding
Tools & malware (8)
NDiskMonitor · QuasarRAT · BackConfig · TINYTYPHON · AutoIt backdoor · PowerSploit · BADNEWS · Unknown Logger
Reporting (3)
- Updated BackConfig Malware Targeting Government and Military Organizations in South Asia — Hinchliffe, A. and Falcone, R
- Patchwork APT Group Targets US Think Tanks — Meltzer, M, et al
- Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent — Levene, B. et al.