Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Patchwork

Also known as: Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover, Capricorn Organisation, APT-C-09, Viceroy Tiger, Offshore APT organization from South Asia, Asia, Donot Team, APT-C-35, SectorE02, Orange Kala, Patchwork, Sarit, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, APTC35

Description

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.(Citation: Cymmetria Patchwork) (Citation: Symantec Patchwork)(Citation: TrendMicro Patchwork Dec 2017)(Citation: Volexity Patchwork June 2018)

TTP Summary

Hangover; Monsoon

Goals & Targeting

Targeted Sectors

Defense
Government
Ngo

Targeted Countries / Regions

IN
middle_east
europe
SA

AI Analysis

· 1 week ago

Executive Summary

Patchwork, also known as Hangover Group or Dropping Elephant, is a cyber espionage group targeting defense, government, and NGO sectors globally. The group has been active since December 2015 and is suspected to have ties to an Indian pro-Indian entity. Patchwork uses basic tools and techniques, often sourced from online forums, but remains effective due to its operational stealth and persistence.

Goals & Targeting

Patchwork's primary motivation appears to be espionage, with a focus on collecting sensitive information from government and defense sector targets. The group's global targeting across regions like India, the Middle East, Europe, and South Asia suggests a broad intelligence-gathering objective. Typical victims include diplomatic agencies, think tanks, and organizations involved in geopolitical activities, aligning with its suspected pro-Indian or Indian entity origins.

Enhanced Description

Patchwork is a cyber espionage group that was first observed in December 2015. The group has not been definitively attributed to a specific nation-state or actor, though circumstantial evidence suggests possible Indian origin or influence. Patchwork primarily targets diplomatic and government agencies, with campaigns observed targeting the defense sector, NGOs, and government institutions across India, the Middle East, Europe, and South Asia. The group is known for its use of basic tools and techniques, often copying code from online forums, which contributes to its lower sophistication level compared to other APT groups. Despite this, Patchwork has demonstrated persistence and stealth in its operations, making it a significant threat to its targeted sectors.

Key Capabilities

  • Use of basic tools and techniques often sourced from online forums
  • Spearphishing campaigns targeting specific sectors
  • Distribution of malicious links via phishing emails
  • Use of scheduled tasks for persistence
  • Code signing to enhance campaign credibility
  • Removal of indicators of compromise from tools

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1053.005
T1132.001
T1074.001
T1036.005
T1204.002
T1553.002
T1587.002
T1059.001
T1027.001
T1070.004
T1083
T1027.002
T1055.012

Software / Tooling

TINYTYPHON
Unknown Logger
BackConfig
NDiskMonitor
BADNEWS
AutoIt backdoor

Campaigns & Victims

Patchwork has been involved in several notable campaigns, including Operation Hangover and Monsoon. These campaigns have targeted U.S. think tanks and Indian government agencies, respectively. The group is known for its persistence and ability to remain active despite being monitored by cybersecurity researchers. Patchwork's operations often involve spearphishing links targeting victims in the defense and diplomatic sectors.

IOC Patterns

  • Spearphishing campaigns with malicious links
  • Use of scheduled tasks for persistence
  • Code signing certificates for malicious binaries
  • Distribution of malicious files via phishing emails

Recommended Actions

  • Monitor for suspicious scheduled task activity
  • Enhance email filtering to detect spearphishing links
  • Implement endpoint detection and response (EDR) solutions
  • Conduct regular audits of system configurations for signs of unauthorized changes
  • Educate employees on phishing tactics and suspicious emails

Suggested Tags

APT
espionage
government
defense
NGO
south_asia

Confidence Assessment

There is moderate confidence in the data regarding Patchwork's activities, given the circumstantial evidence linking it to pro-Indian or Indian-origin entities. However, definitive attribution remains unclear, and some aspects of its toolset and campaign patterns are not fully understood.

ATT&CK Techniques

Discovery
5 techniques
Execution
8 techniques
Stealth
9 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 5 Domain 2 IPv4 Address 13

References

  1. Cymmetria Patchwork — Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.
  2. Operation Hangover May 2013 — Fagerland, S., et al. (2013, May). Operation Hangover: Unveiling an Indian Cyberattack Infrastructure. Retrieved November 17, 2024.
  3. Symantec Patchwork — Hamada, J.. (2016, July 25). Patchwork cyberespionage group expands targets from governments to wide range of industries. Retrieved August 17, 2016.
  4. Unit 42 BackConfig May 2020 — Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.
  5. Securelist Dropping Elephant — Kaspersky Lab's Global Research & Analysis Team. (2016, July 8). The Dropping Elephant – aggressive cyber-espionage in the Asian region. Retrieved August 3, 2016.
  6. PaloAlto Patchwork Mar 2018 — Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.
  7. TrendMicro Patchwork Dec 2017 — Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.
  8. Volexity Patchwork June 2018 — Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.
  9. Forcepoint Monsoon — Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

Intel Summary

41

Techniques

9

Tools

3

Campaigns

279

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
Phishing
Government Targeting
espionage
government
defense
NGO
south_asia

Details

MITRE ID
G0040
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--17862c7d-9e60-48a0-b48e-da4dc4c3f6b0
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.