Patchwork
MITRE ATT&CK: G0040 View on attack.mitre.org
Aliases: Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover, Patchwork, Monsoon, Sarit, APT-C-09, ZINC EMERSON, ATK11, Orange Athos, Thirsty Gemini
- First seen
- 2015-12-01 00:00:00
- Origin
- IN
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- Espionage
- Related IoCs
- 5 (5 malicious)
- Last IoC activity
- 2026-03-03 18:04:25
- Profile updated
- 2026-07-07 12:31:35
Targeted industries: government-and-public-sector education-and-nonprofits professional-services
Targeted regions: country_code:us
Context
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.
Recent IoC activity
5 malicious indicators in Maltiverse are attributed to Patchwork (G0040). The 5 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | a943b5b03b31604830766f41187f65dff2f18d9f7dcdb4241b375a5d95aaa043 | 2026-03-03 | 1 |
| file sample | 8ffdc7d783f87eab110921b33c74867a5eed7566d67d943f8d7deb5659d60c27 | 2026-03-03 | 1 |
| file sample | 79192cba1c7037e1fe15dbf50bb2b3a96e53a85fbcbd2ce229af0efacdcb73c7 | 2026-03-03 | 1 |
| file sample | 6c4c388acbd9790526cc7e8c567e430540436da94c6febe0766a1bdc39016da7 | 2026-03-03 | 1 |
| file sample | 263f1db1c1eafd6757f7ca97bd9eef9c4df026777d1d5db133c4482e9e70251b | 2026-03-03 | 1 |
Detection coverage
- 7 YARA rules
- 864 Sigma rules
Malware & tools used
- Archive Collected Data (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Code Signing (attack-pattern)
- DLL (attack-pattern)
- Modify Registry (attack-pattern)
- BITS Jobs (attack-pattern)
- Indicator Removal from Tools (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Scheduled Task (attack-pattern)
- Standard Encoding (attack-pattern)
- Process Hollowing (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Local Data Staging (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Command Obfuscation (attack-pattern)
- Tool (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Malicious Link (attack-pattern)
- Security Software Discovery (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Software Packing (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Data from Local System (attack-pattern)
Related threat objects
- MONSOON (threat-actor)
Reports & references
- pwc.com — Yir Cyber Threats Report Download (report)
- Palo Alto Unit 42 — Updated Backconfig Malware Targeting Government And Military Organizations (report)
- Broadcom/Symantec — Viewdocument (report)
- forcepoint.com — Monsoon Analysis Apt Campaign (report)
- cymmetria.com — Patchwork Targeted Attack (report)
- s3-us-west-2.amazonaws.com — Unveiling Patchwork (report)
- volexity.com — Patchwork Apt Group Targets Us Think Tanks (report)
- MITRE ATT&CK — G0040 (report)
- Trend Micro — Tech Brief Untangling The Patchwork Cyberespionage Group (report)
- Kaspersky — 75328 (report)
- forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
- secureworks.com — Zinc Emerson (report)
- ti.qianxin.com — Analysis Of The Attack Activities Of Patchwork Using The Documents Of Relevant Government Agencies In Pakistan As Bait (report)
- Palo Alto Unit 42 — Thirstygemini (report)
- Broadcom/Symantec — Patchwork Cyberespionage Group Expands Targets Governments Wide Range Industries (report)
- researchcenter.paloaltonetworks.com — Unit42 Patchwork Continues Deliver Badnews Indian Subcontinent (report)
- web.archive.org — Unveiling An Indian Cyberattack Infrastructure (report)
- web.archive.org — Unveiling Patchwork (report)
External references
- mitre-attack — G0040
- Patchwork
- Chinastrats
- Dropping Elephant
- Hangover Group
- Cymmetria Patchwork
- Operation Hangover May 2013
- Symantec Patchwork
- Unit 42 BackConfig May 2020
- Operation Hangover
- Securelist Dropping Elephant
- PaloAlto Patchwork Mar 2018
- TrendMicro Patchwork Dec 2017
- Volexity Patchwork June 2018
- MONSOON
- Forcepoint Monsoon
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy