Patchwork, an advanced persistent threat group also known as Monsoon, Dropping Elephant, and Hangover Group, has launched a new espionage campaign characterized by the use of sophisticated malware delivery techniques. The campaign begins with the distribution of malicious Microsoft Office documents containing illicit macros, which, when executed, trigger PowerShell scripts on the victim's system. These scripts are designed to download a trojanized executable that masquerades as the VLC media player, furthering the deception. The malware then sideloads a fake DLL library, a technique that allows it to evade detection by security software and gain persistence on the infected machine. To further obfuscate its activities, the malware injects a decoy PDF file into the Public Documents folder, likely to distract users and security analysts. A scheduled task is established in Windows to ensure the malicious executable is triggered regularly, maintaining the attacker's foothold. The final Patchwork payload is then loaded, enabling the threat actors to conduct extensive espionage operations. Technical analysis revealed that the malware uses Scourgify encoding to exfiltrate command outputs, making detection and analysis more challenging. The malware is also capable of running commands that segment large files, allocate executable memory, and capture full-screen screenshots, providing attackers with comprehensive surveillance capabilities. The campaign demonstrates a high level of modularity, allowing Patchwork to adapt its tactics and payloads as needed. Security researchers have recommended that organizations implement robust endpoint protection solutions to defend against such modular and stealthy threats. The use of DLL sideloading and layered obfuscation techniques highlights Patchwork's ongoing evolution and sophistication in cyber-espionage. The campaign's reliance on PowerShell-based loaders and scheduled tasks underscores the importance of monitoring script execution and task creation within enterprise environments. The attack chain leverages both social engineering, through malicious documents, and technical stealth, through obfuscation and sideloading. Patchwork's activities in this campaign are consistent with its historical focus on espionage against government and strategic targets. The campaign's discovery was attributed to detailed analysis by K7 Security Labs, which provided insights into the malware's operation and recommended defensive measures. Organizations are urged to educate users about the risks of enabling macros in Office documents and to monitor for unusual scheduled tasks and PowerShell activity. The campaign serves as a reminder of the persistent and evolving nature of APT threats targeting sensitive information.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting disclosed that the malware chain dropped a decoy PDF, sideloaded a fake DLL, and used Scourgify encoding to exfiltrate command output. Analysts also noted capabilities including file chunking, executable memory allocation, and full-screen screenshot capture and upload.
K7 Security Labs reported a new Patchwork APT espionage campaign using malicious Office documents with macros, a PowerShell-based loader, DLL sideloading, and Windows Scheduled Tasks to deploy the final payload. The campaign also used layered obfuscation and spoofed a VLC media player executable to evade detection.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.