Patchwork is a long-running cyber-espionage threat actor widely associated with Indian state interests and tracked under aliases including Dropping Elephant, Monsoon, Operation Hangover, Quilted Tiger, APT-C-09, ChinaStrats, Patchwork APT, and Zinc Emerson. Reporting has also linked the broader Operation Hangover and Monsoon activity clusters to Indian surveillance and espionage efforts, and some research has noted overlaps between Patchwork and other India-linked operators. Patchwork has historically focused on intelligence collection against regional strategic targets, including government, military, diplomatic, and other entities of geopolitical interest in South Asia and neighboring regions. Pakistan has repeatedly appeared as a primary target set, and the group has also been linked to operations involving Chinese interests and other regional adversaries. The actor is known for spearphishing-led intrusions that rely heavily on social engineering and user execution. Common delivery mechanisms include malicious Microsoft Office documents with embedded macros, lure documents themed to current political, military, or regional issues, and more recently malicious shortcut files used to launch PowerShell-based downloaders. Patchwork has demonstrated continued refinement of its tooling, including staged loaders, in-memory payload execution, DLL side-loading, and remote access trojans delivered through decoy content. In at least one documented campaign tracked as Dropping Elephant, the group used a themed lure to deploy a heavily reworked memory-resident RAT via PowerShell staging, abuse of a legitimate Microsoft binary for side-loading, scheduled-task persistence, dynamic API resolution, anti-analysis checks, and encrypted command-and-control traffic. Patchwork malware commonly performs broad host reconnaissance after compromise. Observed behaviors include collecting the victim computer name, username, administrative context, operating system version, processor architecture, and available drives; enumerating files and directories; and identifying installed security software. The group has searched local drives for documents matching targeted extensions, developed file-stealing components to harvest files of interest, and uploaded collected data to command-and-control infrastructure. It has also checked for the presence of defensive products before proceeding with follow-on activity. For persistence, Patchwork has used Windows startup mechanisms such as Startup folder placement and Registry Run keys. Additional observed tradecraft includes modification or deletion of Microsoft Office resiliency-related registry data, likely to reduce visible signs of document crashes or execution issues and improve social-engineering effectiveness. The group has also used Base64-encoded command-and-control traffic in some operations. Patchwork has expanded beyond Windows espionage tooling into mobile surveillance. The actor has been attributed with high confidence to Android campaigns involving trojanized applications carrying the VajraSpy malware family. These apps, often disguised as messaging or news applications and in some cases distributed through official app stores, supported surveillance functions such as theft of contacts, SMS messages, call logs, files, location data, installed application lists, and notifications. More capable variants were able to intercept communications from popular messaging platforms, record calls and ambient audio, log keystrokes, and capture images. These Android operations were assessed as primarily targeting users in Pakistan and were reportedly supported by social-engineering approaches including honey-trap style lures. Patchwork remains notable for its persistence, regional focus, and iterative development of espionage tooling across desktop and mobile platforms. Its operations consistently emphasize credentialed or user-assisted initial access, host profiling, document theft, stealthy persistence, and modular surveillance capabilities aligned with strategic intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
...has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158...
Patchwork... previously exploited CVE-2017-8570, CVE-2012-1856...
...exploited Microsoft vulnerabilities, including CVE-2014-4114...
APT41 leveraged the follow exploits... CVE-2015-1641...
...used exploits for... Word (CVE-2017-0199)...
4 more CVEs tied to this actor tracked in Mallory.
1,034 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a related actor due to reported infrastructure and code-signing certificate overlap with DoNot, suggesting resource sharing.
Conducting a refined malware campaign using a China-themed lure, malicious LNK files, PowerShell downloaders, DLL side-loading, and an in-memory RAT with persistence via a scheduled task.
Conducting a malware campaign using a China-themed lure, PowerShell staging, scheduled task persistence, DLL side-loading via Fondue.exe, and an in-memory RAT delivered through Donut shellcode with hardened HTTPS C2 and anti-analysis features.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.