Patchwork

MITRE ATT&CK: G0040 View on attack.mitre.org

Aliases: Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover, Patchwork, Monsoon, Sarit, APT-C-09, ZINC EMERSON, ATK11, Orange Athos, Thirsty Gemini

First seen
2015-12-01 00:00:00
Origin
IN
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
Espionage
Related IoCs
5 (5 malicious)
Last IoC activity
2026-03-03 18:04:25
Profile updated
2026-07-07 12:31:35

Targeted industries: government-and-public-sector education-and-nonprofits professional-services

Targeted regions: country_code:us

Context

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.

Recent IoC activity

5 malicious indicators in Maltiverse are attributed to Patchwork (G0040). The 5 most recently updated:

Detection coverage

  • 7 YARA rules
  • 864 Sigma rules

Malware & tools used

  • Archive Collected Data (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • DLL (attack-pattern)
  • Modify Registry (attack-pattern)
  • BITS Jobs (attack-pattern)
  • Indicator Removal from Tools (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Tool (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Malicious Link (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Software Packing (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Data from Local System (attack-pattern)

Related threat objects

Reports & references

  • pwc.com — Yir Cyber Threats Report Download (report)
  • Palo Alto Unit 42 — Updated Backconfig Malware Targeting Government And Military Organizations (report)
  • Broadcom/Symantec — Viewdocument (report)
  • forcepoint.com — Monsoon Analysis Apt Campaign (report)
  • cymmetria.com — Patchwork Targeted Attack (report)
  • s3-us-west-2.amazonaws.com — Unveiling Patchwork (report)
  • volexity.com — Patchwork Apt Group Targets Us Think Tanks (report)
  • MITRE ATT&CK — G0040 (report)
  • Trend Micro — Tech Brief Untangling The Patchwork Cyberespionage Group (report)
  • Kaspersky — 75328 (report)
  • forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
  • secureworks.com — Zinc Emerson (report)
  • ti.qianxin.com — Analysis Of The Attack Activities Of Patchwork Using The Documents Of Relevant Government Agencies In Pakistan As Bait (report)
  • Palo Alto Unit 42 — Thirstygemini (report)
  • Broadcom/Symantec — Patchwork Cyberespionage Group Expands Targets Governments Wide Range Industries (report)
  • researchcenter.paloaltonetworks.com — Unit42 Patchwork Continues Deliver Badnews Indian Subcontinent (report)
  • web.archive.org — Unveiling An Indian Cyberattack Infrastructure (report)
  • web.archive.org — Unveiling Patchwork (report)

External references