LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0128: BADNEWS

BADNEWS is malware that has been used by the actors responsible for the Patchwork campaign. Its name was given due to its use of RSS feeds, forums, and blogs for command and control. [1] [2]

EnterpriseS0128MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

BADNEWS matters because it represents a Windows malware family tied in ATT&CK to the Patchwork campaign and to behaviors that support espionage-style operations: persistence, command and control through web/RSS/forum/blog-style channels, discovery, collection from local/removable/network sources, keylogging, screen capture, staging, and tool transfer. For leaders, the decision value is not the malware name itself, but whether the organization can see and contain a Windows endpoint that blends C2 into normal web activity while collecting sensitive files and user input.

Executive priority

Prioritize this as a resilience and evidence question for Windows environments that handle sensitive diplomatic, government, or similar high-value information. Executives should ask whether SOC and IR teams can prove visibility across endpoint persistence, suspicious web-based C2, removable media, network share access, and credential-risk behaviors such as keylogging. Because ATT&CK provides no official detection text or current exploitation claim for this object, investment decisions should focus on validating control coverage against the mapped techniques rather than treating BADNEWS as a standalone indicator-based threat.

Technical view

BADNEWS is listed for Windows and is related to techniques spanning persistence via Scheduled Task and Registry Run Keys/Startup Folder, execution via Windows Command Shell and Native API, stealth via invalid code signatures, resource-name/location matching, and process hollowing, collection from local systems/removable media/network shares, keylogging, screenshots, automated collection, local staging, and C2 using web protocols, web services, encoding, symmetric cryptography, dead-drop resolver, bidirectional communication, and ingress tool transfer. SOC teams should validate that detections correlate endpoint process, persistence, file access, and network web telemetry rather than relying on static malware names or IOCs.

Likely telemetry

  • Windows process creation and command-line telemetry, especially cmd.exe and child-process chains
  • Scheduled Task creation/modification and task execution records
  • Registry Run key and Startup folder modification events
  • Endpoint file creation, rename, and path telemetry for legitimate-looking names or locations
  • Code-signature validation results, including invalid or suspiciously copied signature metadata

Detection direction

  • Build coverage around the related ATT&CK behaviors rather than the BADNEWS name alone, since no official ATT&CK detection guidance is provided.
  • Correlate persistence events with new or unusual binaries, invalid signatures, suspicious naming, and subsequent outbound web traffic.
  • Tune web-C2 analytics carefully: RSS feeds, forums, blogs, and legitimate web services can be normal business traffic, so prioritize rare destinations, unusual user-agent/process associations, beacon-like patterns, and endpoint-to-network correlation.
  • Validate collection analytics for access to local files, removable media, and network shares, especially when followed by staging or outbound web communication.
  • Review false positives from administrative scripts, backup tools, software updaters, and legitimate scheduled tasks before escalating.

Mitigation priorities

  • Confirm Windows endpoint visibility and response capability first: process creation, persistence changes, file activity, removable media, and network connections.
  • Harden persistence surfaces by controlling and monitoring Scheduled Tasks, Run keys, and Startup folders.
  • Use application control and code-signing validation to reduce execution of unsigned or invalidly signed binaries where operationally feasible.
  • Apply least privilege to sensitive local paths and network shares, and reduce unnecessary access from standard user workstations.
  • Govern removable media usage and logging for systems that can access sensitive data.
Additional notes and limits

ATT&CK links BADNEWS to Patchwork use and to a broad set of behaviors that are useful for defensive validation. The Patchwork description notes cyber espionage activity and targeting of diplomatic and government-related industries, while also stating attribution is not definitive. Glexia would treat this object as a control-mapping and telemetry-validation use case: can the environment detect a Windows implant that persists, collects sensitive data, and communicates over web channels that may appear legitimate?

The supplied ATT&CK object has no official detection text, no aliases, no labels, and no object-level tactics specified. No IOCs, current activity claims, victim exposure, or guaranteed detections are provided. Several related techniques list platforms beyond Windows, but the BADNEWS object itself is supplied as Windows; local applicability should be confirmed against the actual estate and available telemetry.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BADNEWS

BADNEWS is malware that has been used by the actors responsible for the Patchwork campaign. Its name was given due to its use of RSS feeds, forums, and blogs for command and control. [1] [2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

24 rows
DomainIDNameRelationship / procedure
EnterpriseT1102.001Dead Drop ResolverSub-technique

BADNEWS collects C2 information via a dead drop resolver.[1][3][2]

EnterpriseT1071.001Web ProtocolsSub-technique

BADNEWS establishes a backdoor over HTTP.[3]

EnterpriseT1113Screen Capture

BADNEWS has a command to take a screenshot and send it to the C2 server.[1][3]

EnterpriseT1005Data from Local System

When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.[1][3]

EnterpriseT1573.001Symmetric CryptographySub-technique

BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23.[1][2]

EnterpriseT1574.001DLLSub-technique

BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable.[1][3]

EnterpriseT1132Data Encoding

After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64.[1]

EnterpriseT1056.001KeyloggingSub-technique

When it first starts, BADNEWS spawns a new thread to log keystrokes.[1][3][2]

EnterpriseT1102.002Bidirectional CommunicationSub-technique

BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs.[1][3][2]

EnterpriseT1036.001Invalid Code SignatureSub-technique

BADNEWS is sometimes signed with an invalid Authenticode certificate in an apparent effort to make it look more legitimate.[2]

EnterpriseT1119Automated Collection

BADNEWS monitors USB devices and copies files with certain extensions to a predefined directory.[2]

EnterpriseT1053.005Scheduled TaskSub-technique

BADNEWS creates a scheduled task to establish by executing a malicious payload every subsequent minute.[3]

EnterpriseT1039Data from Network Shared Drive

When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.[1]

EnterpriseT1132.001Standard EncodingSub-technique

BADNEWS encodes C2 traffic with base64.[1][3][2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

BADNEWS installs a registry Run key to establish persistence.[1]

EnterpriseT1025Data from Removable Media

BADNEWS copies files with certain extensions from USB devices to a predefined directory.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

BADNEWS is capable of executing commands via cmd.exe.[1][2]

EnterpriseT1055.012Process HollowingSub-technique

BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process.[1][2]

EnterpriseT1105Ingress Tool Transfer

BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.[1][3][2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

BADNEWS attempts to hide its payloads using legitimate filenames.[3]

EnterpriseT1106Native API

BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute.[1][2]

EnterpriseT1074.001Local Data StagingSub-technique

BADNEWS copies documents under 15MB found on the victim system to is the user's %temp%\SMB\ folder. It also copies files from USB devices to a predefined directory.[1][2]

EnterpriseT1083File and Directory Discovery

BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory.[2]

EnterpriseT1120Peripheral Device Discovery

BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message.[1][2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0040: Patchwork

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.[1] [2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
1142d9b5df78c2e9...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle1142d9b5df78…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  2. [2]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  3. [3]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  4. [4]
    BADNEWS

    (Citation: Forcepoint Monsoon)

  5. [5]
    BADNEWS

    (Citation: Forcepoint Monsoon)

  6. [6]
    BADNEWS

    (Citation: Forcepoint Monsoon)

  7. [7]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  8. [8]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  9. [9]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  10. [10]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  11. [11]
    mitre-attackS0128
    Open source URL
  12. [12]
    mitre-attackS0128
    Open source URL
  13. [13]
    mitre-attackS0128
    Open source URL
  14. [14]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  15. [15]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  16. [16]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  17. [17]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  18. [18]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  19. [19]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  20. [20]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  21. [21]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  22. [22]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  23. [23]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  24. [24]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  25. [25]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  26. [26]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  27. [27]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  28. [28]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  29. [29]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  30. [30]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  31. [31]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  32. [32]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  33. [33]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  34. [34]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  35. [35]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  36. [36]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  37. [37]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  38. [38]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  39. [39]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  40. [40]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  41. [41]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  42. [42]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  43. [43]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  44. [44]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  45. [45]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  46. [46]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  47. [47]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  48. [48]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  49. [49]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  50. [50]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  51. [51]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  52. [52]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  53. [53]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  54. [54]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  55. [55]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  56. [56]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  57. [57]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  58. [58]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  59. [59]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  60. [60]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  61. [61]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  62. [62]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  63. [63]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  64. [64]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  65. [65]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  66. [66]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  67. [67]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  68. [68]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  69. [69]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  70. [70]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  71. [71]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  72. [72]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  73. [73]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  74. [74]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  75. [75]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  76. [76]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  77. [77]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  78. [78]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  79. [79]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  80. [80]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  81. [81]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  82. [82]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  83. [83]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  84. [84]
    PaloAlto Patchwork Mar 2018

    Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

    Open source URL
  85. [85]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  86. [86]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  87. [87]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  88. [88]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  89. [89]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  90. [90]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  91. [91]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  92. [92]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  93. [93]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  94. [94]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  95. [95]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.