Vexday analysis
Patchwork (também conhecido como Hangover Group, Dropping Elephant, Chinastrats, MONSOON e Operation Hangover) é um grupo de espionagem cibernética observado pela primeira vez em dezembro de 2015, com evidências circunstanciais que sugerem origem indiana ou alinhamento pró-Índia. O grupo tem como alvos preferenciais agências governamentais e entidades diplomáticas, e parte significativa do código utilizado em suas operações foi copiada de fóruns públicos online. Em março e abril de 2018, o Patchwork conduziu campanhas de spearphishing direcionadas a grupos de think tank nos Estados Unidos. O grupo possui 41 técnicas documentadas no MITRE ATT&CK (identificador G0040) e 7 CVEs atribuídas.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 41
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities 7
CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.
Known infrastructure 439
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
196.251.121.52:56001Quasar RATthreatfox45.131.3.38:8443Quasar RATthreatfoxhttp://fd.etmse.com:8080/fd?n=p2.exeQuasar RATthreatfox20.52.184.247:8080Quasar RATthreatfox20.52.184.247:7000Quasar RATthreatfox38.18.231.159:8080Quasar RATthreatfox194.26.192.168:9110Quasar RATthreatfox20.109.157.64:4444Quasar RATthreatfox85.137.56.145:4782Quasar RATthreatfoxzero2six1.duckdns.orgQuasar RATthreatfox207.189.27.144:9876Quasar RATthreatfoxkns.grotominpgroup.plQuasar RATthreatfoxbns.grotominpgroup.plQuasar RATthreatfoxupdate.ddns.netQuasar RATthreatfox41.41.128.115:5005Quasar RATthreatfoxcba5d54230e862787080f0b881f38b2fQuasar RATthreatfoxc16923aa6b647fe1b8e8b2879fc251e48d1f09b34351056d7afe83b18efcdbf6Quasar RATthreatfox502d908a2040f5b23cbb087584247095c9cbb4a3Quasar RATthreatfox217.69.9.252:3252Quasar RATthreatfoxmb66.couponsQuasar RATthreatfoxga888.freeQuasar RATthreatfoxmb66a.meQuasar RATthreatfox789bet.doctorQuasar RATthreatfox8chicharrara.sa.comQuasar RATthreatfoxijdo-ydo.nlQuasar RATthreatfoxfly88gg.stQuasar RATthreatfoxsulebet.liveQuasar RATthreatfoxmb66.pizzaQuasar RATthreatfoxdafacodabac52.fitQuasar RATthreatfoxmb663rd.comQuasar RATthreatfox+439 indicators in total. See them all on the IOCs page.
References
Patchwork uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →