Also known as: Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover, Capricorn Organisation, APT-C-09, Viceroy Tiger, Offshore APT organization from South Asia, Asia, Donot Team, APT-C-35, SectorE02, Orange Kala, Patchwork, Sarit, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, APTC35
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.(Citation: Cymmetria Patchwork) (Citation: Symantec Patchwork)(Citation: TrendMicro Patchwork Dec 2017)(Citation: Volexity Patchwork June 2018)
Hangover; Monsoon
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Patchwork, also known as Hangover Group or Dropping Elephant, is a cyber espionage group targeting defense, government, and NGO sectors globally. The group has been active since December 2015 and is suspected to have ties to an Indian pro-Indian entity. Patchwork uses basic tools and techniques, often sourced from online forums, but remains effective due to its operational stealth and persistence.
Goals & Targeting
Patchwork's primary motivation appears to be espionage, with a focus on collecting sensitive information from government and defense sector targets. The group's global targeting across regions like India, the Middle East, Europe, and South Asia suggests a broad intelligence-gathering objective. Typical victims include diplomatic agencies, think tanks, and organizations involved in geopolitical activities, aligning with its suspected pro-Indian or Indian entity origins.
Enhanced Description
Patchwork is a cyber espionage group that was first observed in December 2015. The group has not been definitively attributed to a specific nation-state or actor, though circumstantial evidence suggests possible Indian origin or influence. Patchwork primarily targets diplomatic and government agencies, with campaigns observed targeting the defense sector, NGOs, and government institutions across India, the Middle East, Europe, and South Asia. The group is known for its use of basic tools and techniques, often copying code from online forums, which contributes to its lower sophistication level compared to other APT groups. Despite this, Patchwork has demonstrated persistence and stealth in its operations, making it a significant threat to its targeted sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Patchwork has been involved in several notable campaigns, including Operation Hangover and Monsoon. These campaigns have targeted U.S. think tanks and Indian government agencies, respectively. The group is known for its persistence and ability to remain active despite being monitored by cybersecurity researchers. Patchwork's operations often involve spearphishing links targeting victims in the defense and diplomatic sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is moderate confidence in the data regarding Patchwork's activities, given the circumstantial evidence linking it to pro-Indian or Indian-origin entities. However, definitive attribution remains unclear, and some aspects of its toolset and campaign patterns are not fully understood.
No observed data linked yet.
41
Techniques
9
Tools
3
Campaigns
279
IOCs
0
Observed Data
13
Tactics