LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0040: Patchwork

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.[1] [2][3][4]

EnterpriseG0040GroupObject v1.7Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0040: Patchwork describes [Patchwork](https://attack.mitre.org/groups/G0040) is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. [Patchwork](https://attack.mitre.org/groups/G0040) has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. [Patchwork](https://attack.mitre.org/groups/G0040) was...

Executive priority

G0040: Patchwork is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0040: Patchwork by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0040: Patchwork appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Patchwork

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.[1] [2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

41 rows
DomainIDNameRelationship / procedure
EnterpriseT1059.005Visual BasicSub-technique

Patchwork used Visual Basic Scripts (VBS) on victim machines.[3][4]

EnterpriseT1560Archive Collected Data

Patchwork encrypted the collected files' path with AES and then encoded them with base64.[3]

EnterpriseT1083File and Directory Discovery

A Patchwork payload has searched all fixed drives on the victim for files matching a specified list of extensions.[1][3]

EnterpriseT1553.002Code SigningSub-technique

Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies.[5]

EnterpriseT1574.001DLLSub-technique

A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading.[3]

EnterpriseT1112Modify Registry

A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs.[3]

EnterpriseT1197BITS Jobs

Patchwork has used BITS jobs to download malicious payloads.[5]

EnterpriseT1027.005Indicator Removal from ToolsSub-technique

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.[3]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data.[1]

EnterpriseT1053.005Scheduled TaskSub-technique

A Patchwork file stealer can run a TaskScheduler DLL to add persistence.[3]

EnterpriseT1132.001Standard EncodingSub-technique

Patchwork used Base64 to encode C2 traffic.[1]

EnterpriseT1055.012Process HollowingSub-technique

A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe.[1]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Patchwork attempted to use RDP to move laterally.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.[1][3]

EnterpriseT1074.001Local Data StagingSub-technique

Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server.[3]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor."[1] They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.[4]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.[1][6][3][4]

EnterpriseT1027.010Command ObfuscationSub-technique

Patchwork has obfuscated a script with Crypto Obfuscator.[3]

EnterpriseT1588.002ToolSub-technique

Patchwork has obtained and used open-source tools such as QuasarRAT.[4]

EnterpriseT1189Drive-by Compromise

Patchwork has used watering holes to deliver files with exploits to initial victims.[2][4]

EnterpriseT1204.001Malicious LinkSub-technique

Patchwork has used spearphishing with links to try to get users to click, download and open malicious files.[2][3][4][5]

EnterpriseT1518.001Security Software DiscoverySub-technique

Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool).[1]

EnterpriseT1203Exploitation for Client Execution

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.[1][6][2][7][3][4][5]

EnterpriseT1027.002Software PackingSub-technique

A Patchwork payload was packed with UPX.[6]

EnterpriseT1033System Owner/User Discovery

Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server.[1][3]

EnterpriseT1005Data from Local System

Patchwork collected and exfiltrated files from the infected system.[1]

EnterpriseT1204.002Malicious FileSub-technique

Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware.[3][4]

EnterpriseT1587.002Code Signing CertificatesSub-technique

Patchwork has created self-signed certificates from fictitious and spoofed legitimate software companies that were later used to sign malware.[5]

EnterpriseT1070.004File DeletionSub-technique

Patchwork removed certain files and replaced them so they could not be retrieved.[3]

EnterpriseT1119Automated Collection

Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server.[3]

EnterpriseT1102.001Dead Drop ResolverSub-technique

Patchwork hides base64-encoded and encrypted C2 server locations in comments on legitimate websites.[6]

EnterpriseT1680Local Storage Discovery

Patchwork enumerated all available drives on the victim's machine.[1][3]

EnterpriseT1059.003Windows Command ShellSub-technique

Patchwork ran a reverse shell with Meterpreter.[1] Patchwork used JavaScript code and .SCT files on victim machines.[3][4]

EnterpriseT1027.001Binary PaddingSub-technique

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.[3]

EnterpriseT1548.002Bypass User Account ControlSub-technique

Patchwork bypassed User Access Control (UAC).[1]

EnterpriseT1059.001PowerShellSub-technique

Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine.[1][3]

EnterpriseT1598.003Spearphishing LinkSub-technique

Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages.[4]

EnterpriseT1105Ingress Tool Transfer

Patchwork payloads download additional files from the C2 server.[6][3]

EnterpriseT1566.002Spearphishing LinkSub-technique

Patchwork has used spearphishing with links to deliver files with exploits to initial victims.[2][3][5]

EnterpriseT1082System Information Discovery

Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server.[1][3]

EnterpriseT1559.002Dynamic Data ExchangeSub-technique

Patchwork leveraged the DDE protocol to deliver their malware.[3]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0042: MONSOON

Official MITRE ATT&CK object mirrored from source data.

Revoked/deprecated
MalwareEnterprise

S0131: TINYTYPHON

TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign. The majority of its code was reportedly taken from the MyDoom worm. [1]

MalwareEnterprise

S0129: AutoIt backdoor

AutoIt backdoor is malware that has been used by the actors responsible for the MONSOON campaign. The actors frequently used it in weaponized .pps files exploiting CVE-2014-6352. [1] This malware makes use of the legitimate scripting language for Windows GUI automation with the same name.

Windows
ToolEnterprise

S0194: PowerSploit

PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration. [1] [2] [3]

Windows
MalwareEnterprise

S0128: BADNEWS

BADNEWS is malware that has been used by the actors responsible for the Patchwork campaign. Its name was given due to its use of RSS feeds, forums, and blogs for command and control. [1] [2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.7
Created
Modified
Raw hash
d4cbb7f9d7792c57...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.7Current bundled4cbb7f9d779…
19.11.7Older bundle29ba5254c884…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Cymmetria Patchwork

    Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.

    Open source URL
  2. [2]
    Symantec Patchwork

    Hamada, J.. (2016, July 25). Patchwork cyberespionage group expands targets from governments to wide range of industries. Retrieved August 17, 2016.

  3. [3]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  4. [4]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  5. [5]
    Unit 42 BackConfig May 2020

    Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.

    Open source URL
  6. [6]
    Securelist Dropping Elephant

    Kaspersky Lab's Global Research & Analysis Team. (2016, July 8). The Dropping Elephant – aggressive cyber-espionage in the Asian region. Retrieved August 3, 2016.

    Open source URL
  7. [7]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  8. [8]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  9. [9]
    Chinastrats

    (Citation: Securelist Dropping Elephant)

  10. [10]
    Dropping Elephant

    (Citation: Symantec Patchwork) (Citation: Securelist Dropping Elephant) (Citation: PaloAlto Patchwork Mar 2018) (Citation: Volexity Patchwork June 2018)

  11. [11]
    Hangover Group

    [Patchwork](https://attack.mitre.org/groups/G0040) and the Hangover Group have both been referenced as aliases for the threat group associated with Operation Monsoon.(Citation: PaloAlto Patchwork Mar 2018)(Citation: Unit 42 BackConfig May 2020)(Citation: Forcepoint Monsoon)

  12. [12]
    MONSOON

    MONSOON is the name of an espionage campaign; we use it here to refer to the actor group behind the campaign. (Citation: Forcepoint Monsoon) (Citation: PaloAlto Patchwork Mar 2018)

  13. [13]
    Operation Hangover

    It is believed that the actors behind [Patchwork](https://attack.mitre.org/groups/G0040) are the same actors behind Operation Hangover. (Citation: Forcepoint Monsoon) (Citation: Operation Hangover May 2013)

  14. [14]
    Operation Hangover May 2013

    Fagerland, S., et al. (2013, May). Operation Hangover: Unveiling an Indian Cyberattack Infrastructure. Retrieved November 17, 2024.

    Open source URL
  15. [15]
    Patchwork

    (Citation: Cymmetria Patchwork) (Citation: Symantec Patchwork) (Citation: Securelist Dropping Elephant) (Citation: PaloAlto Patchwork Mar 2018) (Citation: Volexity Patchwork June 2018)

  16. [16]
    mitre-attackG0040
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.