{"id":509,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2015<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">India (Suspected)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Spear-phishing, BADNEWS malware, targeting Pakistan, China, and Southeast Asian governments<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Dropping Elephant, Chinastrats, Monsoon, Zinc Emerson, TG-4410<\/div>\n  <\/div>\n<\/div>\n<p>Patchwork APT, also tracked as Dropping Elephant and Monsoon, is a suspected Indian state-sponsored threat actor that has been active since at least 2015. The group's unofficial name \"Patchwork\" was assigned by researchers to reflect the group's distinctive operational methodology: assembling their toolset and attack infrastructure from a patchwork of copy-pasted code, publicly available proof-of-concept exploits, and repurposed open-source tools rather than developing bespoke malware from scratch.<\/p>\n<p>The group primarily conducts cyber espionage against Pakistani government and military targets, reflecting India's strategic intelligence priorities in the region. Secondary targeting has been observed against Chinese entities, particularly those involved in the China-Pakistan Economic Corridor (CPEC), as well as think tanks and government agencies across Southeast Asia focused on South Asian affairs.<\/p>\n<p>Patchwork's signature malware, BADNEWS, is distributed through highly targeted spear-phishing campaigns using geopolitically relevant lure documents themed around Pakistani and South Asian affairs. BADNEWS provides remote access, keylogging, screen capture, and file exfiltration capabilities, communicating with command-and-control servers via legitimate cloud services including Dropbox and Google Docs to evade network-based detection.<\/p>\n<p>In a notable operational security failure in 2022, Patchwork operators accidentally infected their own systems with their BADNEWS malware during testing, inadvertently providing researchers with visibility into the group's operational infrastructure, victim list, and internal communications ,  a rare insight into a suspected state-sponsored actor's day-to-day operations.<\/p>\n\n<p><strong>Cyber Espionage Tactics and Persistence Mechanisms:<\/strong> Operational tracking indicates that <strong>Patchwork APT<\/strong> executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.<\/p>","link":"https:\/\/cyberasia.io\/actor\/patchwork-apt\/","name":"Patchwork APT","slug":"patchwork-apt","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}