Patchwork
Also reported as Dropping Elephant, Chinastrats, Donot Team, APT-C-35, SectorE02 and 25 other names. Linked to India by three sources.
Reports per quarter
Techniques seen in the last two years
- T1059.001 3 reports in ATT&CK
- T1071.001 3 reports reports only
- T1583.001 3 reports reports only
- T1027 2 reports reports only
- T1053.005 2 reports in ATT&CK
- T1055 2 reports reports only
- T1082 2 reports in ATT&CK
- T1105 2 reports in ATT&CK
- T1112 2 reports in ATT&CK
- T1140 2 reports reports only
Show all 56 techniques Show fewer
- T1566.001 2 reports in ATT&CK
- T1573.001 2 reports reports only
- T1583.008 2 reports reports only
- T1012 1 report reports only
- T1014 1 report reports only
- T1027.010 1 report in ATT&CK
- T1036 1 report reports only
- T1036.005 1 report in ATT&CK
- T1037.001 1 report reports only
- T1041 1 report reports only
- T1059.003 1 report in ATT&CK
- T1070.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1113 1 report reports only
- T1124 1 report reports only
- T1132 1 report reports only
- T1132.001 1 report in ATT&CK
- T1204.002 1 report in ATT&CK
- T1219 1 report reports only
- T1398 1 report reports only
- T1417.001 1 report reports only
- T1418 1 report reports only
- T1420 1 report reports only
- T1422 1 report reports only
- T1426 1 report reports only
- T1429 1 report reports only
- T1430 1 report reports only
- T1437.001 1 report reports only
- T1481.003 1 report reports only
- T1497 1 report reports only
- T1512 1 report reports only
- T1517 1 report reports only
- T1533 1 report reports only
- T1555.003 1 report in ATT&CK
- T1566.002 1 report in ATT&CK
- T1573.002 1 report reports only
- T1583.003 1 report reports only
- T1583.004 1 report reports only
- T1584.004 1 report reports only
- T1620 1 report reports only
- T1636.002 1 report reports only
- T1636.003 1 report reports only
- T1636.004 1 report reports only
- T1641 1 report reports only
- T1646 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2010-3333 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-11882
- CVE-2012-1856 KEV
- CVE-2012-4792 KEV
- CVE-2013-3900 KEV
- CVE-2013-3906 KEV
- CVE-2014-1761 KEV
- CVE-2014-4114 KEV
- CVE-2014-6352 KEV
- CVE-2015-1635 KEV
Show all 99 CVEs Show fewer
- CVE-2015-1641 KEV
- CVE-2015-2051 KEV
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2016-0034 KEV ransomware
- CVE-2016-0165 KEV
- CVE-2016-1010 KEV
- CVE-2016-3393 KEV
- CVE-2016-4171 KEV
- CVE-2016-9192
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-11292 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-8570 KEV
- CVE-2017-8750
- CVE-2017-8759 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8242
- CVE-2018-8373 KEV
- CVE-2018-8414 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0808 KEV
- CVE-2019-11043 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-1182
- CVE-2019-11932
- CVE-2019-16759 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-5840
- CVE-2019-9489
- CVE-2020-0688 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-34527 KEV ransomware
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0847 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2024-2883
- CVE-2024-43451 KEV
- CVE-2024-4577 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Patchwork, Dropping Elephant - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Patchwork, Dropping Elephant - Threat Group Cards: A Threat Actor Encyclopedia
-
Operation HangOver, Monsoon, Viceroy Tiger
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Operation HangOver, Monsoon, Viceroy Tiger
Show all 222 reports Show fewer
-
Donot Team - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Donot Team - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The DoNot APT
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DoNot Team (APT-C-35) Analysis of Latest Campaign- Sophisticated Excel Macro Attack Targeting Pakistan
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Manul
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-35 GETS A NEW UPGRADE
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of the attack activities of the Maha grass group using the documents of relevant government agencies in Pakistan as bait
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
What’s with the shared VBA code between Transparent Tribe and other threat actors-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What’s with the shared VBA code between Transparent Tribe and other threat actors-
-
ModifiedElephant APT and a Decade of Fabricating Evidence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ModifiedElephant APT and a Decade of Fabricating Evidence
-
ESET Research investigates Donot Team- Cyberespionage targeting military & governments in South Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ESET Research investigates Donot Team- Cyberespionage targeting military & governments in South Asia
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DoNot Go! Do not respawn!
-
Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
APT_trends_report_Q2_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2021_Securelist
-
DoNot APT Group Delivers A Spyware Variant Of Chat App
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DoNot APT Group Delivers A Spyware Variant Of Chat App
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
Donot Team APT Group Is Back To Using Old Malicious Patterns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Donot Team APT Group Is Back To Using Old Malicious Patterns
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
A Deep Dive Into Patchwork APT Group _ Cyble
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A Deep Dive Into Patchwork APT Group _ Cyble
-
APT_trends_report_Q3_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q3_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report-spark-bahamut
-
Threat Assessment- Hangover Threat Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Assessment- Hangover Threat Group
-
Updated BackConfig Malware Targeting Government and Military Organizations in South Asia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Updated BackConfig Malware Targeting Government and Military Organizations in South Asia
-
Updated BackConfig Malware Targeting Government and Military Organizations in South Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Updated BackConfig Malware Targeting Government and Military Organizations in South Asia
-
Donot team organization (APT-C-35) mobile terminal attack activity analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Donot team organization (APT-C-35) mobile terminal attack activity analysis
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Studying Donot Team
-
cybersecurity-threatscape-2019-q3-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q3-eng
-
New PatchWork Spearphishing Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New PatchWork Spearphishing Attack
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The WannaCry hangover
-
APT-C-09 Reappeared as Conflict Intensified Between India and Pakistan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-09 Reappeared as Conflict Intensified Between India and Pakistan
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-09
-
SectorE02 Updates YTY Framework in New Targeted Campaign Against Pakistan Government
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SectorE02 Updates YTY Framework in New Targeted Campaign Against Pakistan Government
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Donot_Group
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
Shifting in the Wind- WINDSHIFT Attacks Target Middle Eastern Governments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shifting in the Wind- WINDSHIFT Attacks Target Middle Eastern Governments
-
2018 APT Summary Report CN version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 APT Summary Report CN version
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 360追日团队APT报告:摩诃草组织(APT-C-09)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Confucius Update: New Tools and Techniques, Further Connections with Patchwork - TrendLabs Security Intelligence Blog
-
HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
-
Bahamut, Confucius and Patchwork Connected to Urpage
The original link failed its last check. Original publisher Detailsfor Bahamut, Confucius and Patchwork Connected to Urpage
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Goldfin Alert | Accenture
-
Patchwork APT Group Targets US Think Tanks | Volexity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork APT Group Targets US Think Tanks | Volexity
-
Patchwork APT Group Targets US Think Tanks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork APT Group Targets US Think Tanks
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Donot Team in South Asia
-
Donot Team Leverages New Framework | NETSCOUT
The original link failed its last check. Original publisher Detailsfor Donot Team Leverages New Framework | NETSCOUT
-
Donot Team Leverages New Modular Malware Framework in South Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Donot Team Leverages New Modular Malware Framework in South Asia
-
Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
-
Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
-
tech-brief-untangling-the-patchwork-cyberespionage-group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor tech-brief-untangling-the-patchwork-cyberespionage-group
-
EHDevel – The story of a continuously improving advanced threat creation toolkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor EHDevel – The story of a continuously improving advanced threat creation toolkit
-
Confucius Says...Malware Families Get Further By Abusing Legitimate Websites
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Confucius Says...Malware Families Get Further By Abusing Legitimate Websites
-
Confucius Says…Malware Families Get Further By Abusing Legitimate Websites
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Confucius Says…Malware Families Get Further By Abusing Legitimate Websites
-
MONSOON - Analysis Of An APT Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MONSOON - Analysis Of An APT Campaign
-
MONSOON – ANALYSIS OF AN APT CAMPAIGN
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MONSOON – ANALYSIS OF AN APT CAMPAIGN
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 摩诃草组织
-
Patchwork cyberespionage group expands targets from governments to wide range of industries
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork cyberespionage group expands targets from governments to wide range of industries
-
The Dropping Elephant - aggressive cyber-espionage in the Asian region
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Dropping Elephant - aggressive cyber-espionage in the Asian region
-
The Dropping Elephant – aggressive cyber-espionage in the Asian region
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Dropping Elephant – aggressive cyber-espionage in the Asian region
-
The Dropping Elephant actor - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Dropping Elephant actor - Securelist
-
Unveiling Patchwork the Copy Paste APT
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Unveiling Patchwork the Copy Paste APT
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
-
Snake In The Grass: Python-based Malware Used For Targeted Attacks
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Snake In The Grass: Python-based Malware Used For Targeted Attacks
-
World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
-
VICEROY TIGER Delivers New Zero-Day Exploit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VICEROY TIGER Delivers New Zero-Day Exploit
-
Operation Hangover - Unveiling An Indian Cyberattack Infrastructure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Hangover - Unveiling An Indian Cyberattack Infrastructure
-
APT Attacks on Indian Cyber Space
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Attacks on Indian Cyber Space
-
Operation Hangover - Unveiling An Indian Cyberattack Infrastructure (Appendix)
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Hangover - Unveiling An Indian Cyberattack Infrastructure (Appendix)
-
Unveiling_an_Indian_Cyberattack_Infrastructure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Unveiling_an_Indian_Cyberattack_Infrastructure
-
Operation Hangover |Executive Summary
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Hangover |Executive Summary
Newest first. Details opens the report in Explore.