🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
PATCHWORK APT

/actor/patchwork-apt/  ·  0 intel reports

Year Established
2015
Attribution
India (Suspected)
Motivation
Espionage
Modus Operandi (MO)
Spear-phishing, BADNEWS malware, targeting Pakistan, China, and Southeast Asian governments
Primary Aliases
Dropping Elephant, Chinastrats, Monsoon, Zinc Emerson, TG-4410

Patchwork APT, also tracked as Dropping Elephant and Monsoon, is a suspected Indian state-sponsored threat actor that has been active since at least 2015. The group's unofficial name "Patchwork" was assigned by researchers to reflect the group's distinctive operational methodology: assembling their toolset and attack infrastructure from a patchwork of copy-pasted code, publicly available proof-of-concept exploits, and repurposed open-source tools rather than developing bespoke malware from scratch.

The group primarily conducts cyber espionage against Pakistani government and military targets, reflecting India's strategic intelligence priorities in the region. Secondary targeting has been observed against Chinese entities, particularly those involved in the China-Pakistan Economic Corridor (CPEC), as well as think tanks and government agencies across Southeast Asia focused on South Asian affairs.

Patchwork's signature malware, BADNEWS, is distributed through highly targeted spear-phishing campaigns using geopolitically relevant lure documents themed around Pakistani and South Asian affairs. BADNEWS provides remote access, keylogging, screen capture, and file exfiltration capabilities, communicating with command-and-control servers via legitimate cloud services including Dropbox and Google Docs to evade network-based detection.

In a notable operational security failure in 2022, Patchwork operators accidentally infected their own systems with their BADNEWS malware during testing, inadvertently providing researchers with visibility into the group's operational infrastructure, victim list, and internal communications , a rare insight into a suspected state-sponsored actor's day-to-day operations.

Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Patchwork APT executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles