Patchwork

APT / StateG0040
Origin🇮🇳 Índia
Techniques (MITRE ATT&CK)41
SourceMITRE ATT&CK
State sponsor: IndiaAttribution confidence: 50%Target categories: Private sector, Military
Targeted regions: Bangladesh · Sri Lanka · Pakistan
Also known as:Hangover GroupDropping ElephantChinastratsMONSOONOperation Hangover

Vexday analysis

Patchwork (também conhecido como Hangover Group, Dropping Elephant, Chinastrats, MONSOON e Operation Hangover) é um grupo de espionagem cibernética observado pela primeira vez em dezembro de 2015, com evidências circunstanciais que sugerem origem indiana ou alinhamento pró-Índia. O grupo tem como alvos preferenciais agências governamentais e entidades diplomáticas, e parte significativa do código utilizado em suas operações foi copiada de fóruns públicos online. Em março e abril de 2018, o Patchwork conduziu campanhas de spearphishing direcionadas a grupos de think tank nos Estados Unidos. O grupo possui 41 técnicas documentadas no MITRE ATT&CK (identificador G0040) e 7 CVEs atribuídas.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity85
Impact: High
T1189T1053.005T1547.001T1548.002T1033T1021.001ENTRYInitial accessDrive-byCompromiseEXECExecutionScheduled TaskPERSPersistenceRegistry Run Keys/ Startup FolderPRIVPrivilege escalationBypass UserAccount ControlDISCDiscoverySystem Owner/UserDiscoveryLATLateral movementRemote DesktopProtocolCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Known infrastructure 110

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port134.122.200.208:8088Quasar RATthreatfox
ip:port134.122.200.212:8088Quasar RATthreatfox
ip:port94.154.34.203:1604Quasar RATthreatfox
md5_hash8ad256c5b786abb5f1552d906df3482aQuasar RATthreatfox
sha1_hashc321593cb3d8e279dfbdcf6d8bb94fac93cdc405Quasar RATthreatfox
sha256_hashb3c2f9ac068664bb861d7f8a59db533810032bc26d75fad48dbd0e2ba26413b2Quasar RATthreatfox
ip:port153.52.162.73:8080Quasar RATthreatfox
ip:port169.58.23.30:22Quasar RATthreatfox
domainvk10.waizerfly.comQuasar RATthreatfox
ip:port202.181.188.64:1488Quasar RATthreatfox
ip:port194.59.30.105:9619Quasar RATthreatfox
ip:port134.122.200.217:8088Quasar RATthreatfox
ip:port20.215.224.217:8080Quasar RATthreatfox
ip:port5.83.150.71:4567Quasar RATthreatfox
ip:port145.63.135.73:4782Quasar RATthreatfox
ip:port178.16.52.35:4433Quasar RATthreatfox
ip:port190.255.83.163:6001Quasar RATthreatfox
urlhttp://217.60.195.219/ty/load.batQuasarRATurlhaus
ip:port5.230.69.252:8443Quasar RATthreatfox
ip:port38.128.251.209:3000Quasar RATthreatfox
ip:port105.108.207.177:288Quasar RATthreatfox
ip:port185.194.30.165:8080Quasar RATthreatfox
ip:port149.30.232.214:46999Quasar RATthreatfox
ip:port20.215.40.6:7000Quasar RATthreatfox
ip:port130.162.224.102:2222Quasar RATthreatfox
md5_hash2ac1f830806ce3bdd35cdcb957f139baQuasar RATthreatfox
sha1_hash00f6a68fef995c15c116c48b18d9611db036c1e5Quasar RATthreatfox
sha256_hash9270d36aa57eec3d44dc2d66929551198cb8a31d0ef383a726c38b75ad8144baQuasar RATthreatfox
ip:port194.59.30.130:5000Quasar RATthreatfox
ip:port38.128.251.36:3000Quasar RATthreatfox

+110 indicators in total. See them all on the IOCs page.

Patchwork uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →