Patchwork — APT Profile
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.Also tracked as
Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover
Tools & malware
- AutoIt backdoor Backdoor
- BackConfig Backdoor
- BADNEWS Backdoor
- NDiskMonitor Backdoor
- PowerSploit Post-Exploitation Framework
- QuasarRAT Remote Access Trojan
- TINYTYPHON Backdoor
- Unknown Logger Backdoor
Vendor research
- Unveiling Patchwork - The Copy-Paste APT Cymmetria
- Operation Hangover: Unveiling an Indian Cyberattack Infrastructure Operation Hangover
- Patchwork cyberespionage group expands targets from governments to wide range of industries Symantec
- Updated BackConfig Malware Targeting Government and Military Organizations in South Asia Unit 42
- The Dropping Elephant – aggressive cyber-espionage in the Asian region Securelist
- Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent PaloAlto
- Untangling the Patchwork Cyberespionage Group TrendMicro
- Patchwork APT Group Targets US Think Tanks Volexity
- MONSOON - Analysis Of An APT Campaign Forcepoint