Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover
41
techniques
8
software
11,647
corpus matches
profile
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.
techniques
41 attributed · most-instrumented first
software
8 malware & tools attributed
BADNEWS
S0128
AutoIt backdoor
S0129
Unknown Logger
S0130
TINYTYPHON
S0131
PowerSploit
S0194
QuasarRAT
S0262
NDiskMonitor
S0272
BackConfig
S0475
read this carefully
11,647 corpus matches is not attribution
That count is indicators which exhibit techniques Patchwork is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+29 more techniques
showing 30 of 11,647
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.