All actors

Patchwork

Also reported as Dropping Elephant, Chinastrats, Donot Team, APT-C-35, SectorE02 and 25 other names. Linked to India by three sources.

Reports
222
Last reported
Known CVEs
99
Techniques in ATT&CK
41
Origin
India
ID
G0040
Merge evidence
39 alias matches

Reports per quarter

  1. 2013 Q2: 3 reports
  2. 2013 Q3: 2 reports
  3. 2013 Q4: 2 reports
  4. 2014 Q1: no reports
  5. 2014 Q2: 1 report
  6. 2014 Q3: 1 report
  7. 2014 Q4: no reports
  8. 2015 Q1: no reports
  9. 2015 Q2: no reports
  10. 2015 Q3: no reports
  11. 2015 Q4: no reports
  12. 2016 Q1: 1 report
  13. 2016 Q2: 1 report
  14. 2016 Q3: 15 reports
  15. 2016 Q4: 2 reports
  16. 2017 Q1: 1 report
  17. 2017 Q2: 3 reports
  18. 2017 Q3: 1 report
  19. 2017 Q4: 2 reports
  20. 2018 Q1: 9 reports
  21. 2018 Q2: 3 reports
  22. 2018 Q3: 7 reports
  23. 2018 Q4: 3 reports
  24. 2019 Q1: 6 reports
  25. 2019 Q2: 3 reports
  26. 2019 Q3: 6 reports
  27. 2019 Q4: 5 reports
  28. 2020 Q1: 5 reports
  29. 2020 Q2: 12 reports
  30. 2020 Q3: no reports
  31. 2020 Q4: 11 reports
  32. 2021 Q1: 5 reports
  33. 2021 Q2: 6 reports
  34. 2021 Q3: 7 reports
  35. 2021 Q4: 5 reports
  36. 2022 Q1: 18 reports
  37. 2022 Q2: 14 reports
  38. 2022 Q3: 4 reports
  39. 2022 Q4: 3 reports
  40. 2023 Q1: 6 reports
  41. 2023 Q2: 3 reports
  42. 2023 Q3: 3 reports
  43. 2023 Q4: 3 reports
  44. 2024 Q1: 3 reports
  45. 2024 Q2: 2 reports
  46. 2024 Q3: 2 reports
  47. 2024 Q4: 1 report
  48. 2025 Q1: 6 reports
  49. 2025 Q2: 2 reports
  50. 2025 Q3: 1 report
  51. 2025 Q4: 3 reports
  52. 2026 Q1: no reports
  53. 2026 Q2: 19 reports
  54. 2026 Q3: 1 report
Dated reports, 2013 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 56 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 28 techniques Show fewer

CVEs named in reports

Show all 99 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  2. Operation HangOver, Monsoon, Viceroy Tiger

    date ORKL added it fromORKL

Show all 222 reports Show fewer
  1. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

  2. Quasar RAT (Malware Family)

    date ORKL added it fromORKL

  3. The DoNot APT

    date in the title fromORKL

  4. Operation Manul

    date ORKL added it EFF fromORKL

  5. APT-C-35 GETS A NEW UPGRADE

    date in the title fromORKL

  6. eset_threat_report_t12022

    file creation date fromORKL

  7. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  8. yir-cyber-threats-report-download.pdf

    Malpedia library date fromORKL

  9. ModifiedElephant APT and a Decade of Fabricating Evidence

    date in the title fromORKL

  10. DoNot Go! Do not respawn!

    date in the title fromORKL

  11. Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  12. APT trends report Q3 2021

    date in the title fromORKL

  13. Report

    Malpedia library date fromORKL

  14. APT_trends_report_Q2_2021_Securelist

    file creation date fromORKL

  15. DoNot APT Group Delivers A Spyware Variant Of Chat App

    date in the title fromORKL

  16. APT_trends_report_Q1_2021_Securelist

    file creation date fromORKL

  17. APT trends report Q1 2021

    date in the title fromORKL

  18. Intezer-2020-Go-Malware-Round-Up.pdf

    Malpedia library date fromORKL

  19. A Deep Dive Into Patchwork APT Group _ Cyble

    date in the CCS '25 data Cyble fromORKLCCS '25 data

  20. APT_trends_report_Q3_2020_Securelist

    file creation date fromORKL

  21. APT trends report Q3 2020

    date in the title fromORKL

  22. report-spark-bahamut

    file creation date fromORKL

  23. Threat Assessment- Hangover Threat Group

    date in the title fromORKL

  24. 200407-MWB-COVID-White-Paper_Final

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  25. cybersecurity-threatscape-2019-q4-eng

    file creation date fromORKL

  26. Studying Donot Team

    date in the CCS '25 data Positive Technologies fromORKLCCS '25 data

  27. cybersecurity-threatscape-2019-q3-eng

    file creation date fromORKL

  28. New PatchWork Spearphishing Attack

    date in the title fromORKL

  29. The WannaCry hangover

    date in the title fromORKL

  30. APT-C-09

    date in the CCS '25 data QiAnXin fromORKLCCS '25 data

  31. Donot_Group

    file creation date fromORKL

  32. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  33. 2018 APT Summary Report CN version

    file creation date fromORKL

  34. 360追日团队APT报告:摩诃草组织(APT-C-09)

    file creation date fromORKL

  35. HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]

    date in the CCS '25 data Bellingcat fromORKLCCS '25 data

  36. Goldfin Alert | Accenture

    file creation date fromORKL

  37. Patchwork APT Group Targets US Think Tanks | Volexity

    date in the CCS '25 data Volexity fromORKLCCS '25 data

  38. Patchwork APT Group Targets US Think Tanks

    date in the title fromORKL

  39. Donot Team in South Asia

    file creation date fromORKL

  40. Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  41. tech-brief-untangling-the-patchwork-cyberespionage-group

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  42. Confucius Says...Malware Families Get Further By Abusing Legitimate Websites

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  43. MONSOON - Analysis Of An APT Campaign

    date in the title fromORKL

  44. MONSOON – ANALYSIS OF AN APT CAMPAIGN

    Malpedia library date Forcepoint fromORKL

  45. 摩诃草组织

    file creation date fromORKL

  46. The Dropping Elephant actor - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  47. Unveiling Patchwork the Copy Paste APT

    date in the CCS '25 data Cymmetria fromORKLCCS '25 data

  48. PowerPoint Presentation

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  49. Snake In The Grass: Python-based Malware Used For Targeted Attacks

    date in the CCS '25 data Bluecoat fromORKLCCS '25 data

  50. VICEROY TIGER Delivers New Zero-Day Exploit

    date in the title fromORKL

  51. Operation Hangover - Unveiling An Indian Cyberattack Infrastructure

    file creation date Norman, Shadowserver fromORKL

  52. APT Attacks on Indian Cyber Space

    file creation date Infosec Consortium fromORKL

  53. Unveiling_an_Indian_Cyberattack_Infrastructure

    Malpedia library date fromORKL

  54. Operation Hangover |Executive Summary

    file creation date Norman fromORKL

Newest first. Details opens the report in Explore.