Patchwork, also tracked as Dropping Elephant, has been linked to a cross-platform espionage campaign that used fake PDF lures on Windows and trojanized chat applications on Android to surveil victims across multiple sectors and regions. Reported targets included organizations in government, defense, energy, research, aviation, finance, and technology across Asia, Europe, Türkiye, and the United States, indicating a broad intelligence-collection effort rather than opportunistic cybercrime.
On Windows, the operation reportedly relied on a malicious .lnk file disguised as a PDF that launched PowerShell, opened a decoy document, created persistence through scheduled tasks, and deployed a remote access tool using DLL side-loading and in-memory payload decryption. On Android, the group used romance-themed social engineering to persuade victims to sideload fake messaging apps such as Wave Chat, enabling theft of chats, keystrokes, contacts, files, call data, audio, and camera feeds; reporting on the campaign also cited associated indicators of compromise including domains, URL paths, package names, and malware filenames.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
The reporting states that Patchwork, also known as Dropping Elephant, has been active since at least 2015. This establishes the earliest explicit time anchor for the threat actor discussed in the campaign coverage.
The reporting disclosed indicators of compromise tied to the campaign, including delivery and command-and-control domains such as expouav[.]org, roseserve[.]org, chinagreenenergy[.]org, fich[.]buzz, and gcl-power[.]org, as well as the Android package com.yoho.talk. One staging URL under chinagreenenergy[.]org was identified as retrieving both the decoy PDF and additional campaign components.
On Android, Patchwork used romance-themed social engineering to persuade targets to install malicious chat applications outside official app stores, including an identified app named Wave Chat. The implant could steal chats, keystrokes, notifications, contacts, messages, files, call data, audio, and camera captures, and it could persist after reboot.
The Windows malware created scheduled tasks named GoogleErrorReport and NewErrorReport for persistence and abused files such as Fondue.exe, vlc.exe, APPWIZ.cpl, libvlc.dll, vlc.log, and editor.dat to side-load and decrypt payloads. The final remote access tool was loaded in memory inside trusted Windows processes and could collect system data, execute commands, capture screenshots, and exfiltrate selected files.
In the Windows intrusion chain, Patchwork used a malicious shortcut file named GRES3001.lnk disguised as a PDF themed around a China-related energy contract. Opening it launched PowerShell via conhost.exe, displayed a decoy PDF, and retrieved additional malicious components.
Picus Security identified a Patchwork espionage campaign targeting Windows PCs and Android devices with fake PDF lures and trojanized chat applications. The activity reportedly targeted government, defense, energy, research, aviation, financial, and technology organizations across Asia, Europe, Türkiye, and the United States.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcepicussecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.