Patchwork

APT / StateG0040 ↗
Origin🇮🇳 Índia
Techniques (MITRE ATT&CK)41
SourceMITRE ATT&CK
State sponsor: IndiaAttribution confidence: 50%Target categories: Private sector, Military
Targeted regions: Bangladesh · Sri Lanka · Pakistan
Also known as:APT-C-09ATK11ChinastratsDropping ElephantG0040Hangover GroupMONSOONMonsoonOperation HangoverOrange AthosSaritThirsty GeminiZINC EMERSON

Vexday analysis

Patchwork (também conhecido como Hangover Group, Dropping Elephant, Chinastrats, MONSOON e Operation Hangover) é um grupo de espionagem cibernética observado pela primeira vez em dezembro de 2015, com evidências circunstanciais que sugerem origem indiana ou alinhamento pró-Índia. O grupo tem como alvos preferenciais agências governamentais e entidades diplomáticas, e parte significativa do código utilizado em suas operações foi copiada de fóruns públicos online. Em março e abril de 2018, o Patchwork conduziu campanhas de spearphishing direcionadas a grupos de think tank nos Estados Unidos. O grupo possui 41 técnicas documentadas no MITRE ATT&CK (identificador G0040) e 7 CVEs atribuídas.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity85
Impact: High
T1189T1053.005T1547.001T1548.002T1033T1021.001ENTRYInitial accessDrive-byCompromiseEXECExecutionScheduled TaskPERSPersistenceRegistry Run Keys/ Startup FolderPRIVPrivilege escalationBypass UserAccount ControlDISCDiscoverySystem Owner/UserDiscoveryLATLateral movementRemote DesktopProtocolCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 7

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 439

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port196.251.121.52:56001Quasar RATthreatfox
ip:port45.131.3.38:8443Quasar RATthreatfox
urlhttp://fd.etmse.com:8080/fd?n=p2.exeQuasar RATthreatfox
ip:port20.52.184.247:8080Quasar RATthreatfox
ip:port20.52.184.247:7000Quasar RATthreatfox
ip:port38.18.231.159:8080Quasar RATthreatfox
ip:port194.26.192.168:9110Quasar RATthreatfox
ip:port20.109.157.64:4444Quasar RATthreatfox
ip:port85.137.56.145:4782Quasar RATthreatfox
domainzero2six1.duckdns.orgQuasar RATthreatfox
ip:port207.189.27.144:9876Quasar RATthreatfox
domainkns.grotominpgroup.plQuasar RATthreatfox
domainbns.grotominpgroup.plQuasar RATthreatfox
domainupdate.ddns.netQuasar RATthreatfox
ip:port41.41.128.115:5005Quasar RATthreatfox
md5_hashcba5d54230e862787080f0b881f38b2fQuasar RATthreatfox
sha256_hashc16923aa6b647fe1b8e8b2879fc251e48d1f09b34351056d7afe83b18efcdbf6Quasar RATthreatfox
sha1_hash502d908a2040f5b23cbb087584247095c9cbb4a3Quasar RATthreatfox
ip:port217.69.9.252:3252Quasar RATthreatfox
domainmb66.couponsQuasar RATthreatfox
domainga888.freeQuasar RATthreatfox
domainmb66a.meQuasar RATthreatfox
domain789bet.doctorQuasar RATthreatfox
domain8chicharrara.sa.comQuasar RATthreatfox
domainijdo-ydo.nlQuasar RATthreatfox
domainfly88gg.stQuasar RATthreatfox
domainsulebet.liveQuasar RATthreatfox
domainmb66.pizzaQuasar RATthreatfox
domaindafacodabac52.fitQuasar RATthreatfox
domainmb663rd.comQuasar RATthreatfox

+439 indicators in total. See them all on the IOCs page.

Patchwork uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →