Patchwork APT Expands Espionage Operations with Stealthy Malware Tactics
The Patchwork APT (also known as Dropping Elephant), a cyber espionage group active since at least December 2015, continues to refine its tactics against high-value targets. The group has historically compromised government, defense, energy, aviation, research, finance, technology, pharmaceutical, NGO, and think tank organizations across Asia, Europe, Türkiye, and the U.S.
Recent campaigns demonstrate evolving techniques, including targeted phishing, deceptive document lures, memory-resident malware, and trojanized Android apps. Attackers deploy fake PDF shortcuts to deliver remote access trojans (RATs), while mobile implants steal messages, files, call records, keystrokes, audio, and images. The group frequently adapts its tools to exploit regional and political themes, such as:
- July 2023: Phishing attacks on Chinese research organizations using the EyeShell backdoor.
- July 2024: Malicious shortcuts and Brute Ratel C4 against Bhutan-linked targets.
- 2025: Conference-themed lures targeting Turkish defense contractors, leveraging VLC DLL side-loading and encrypted payloads.
- June 2026: A China-themed shortcut chain deploying a reworked memory-resident RAT.
Infection Chain & Evasion Tactics
Patchwork’s Windows attacks begin with a malicious .lnk shortcut (e.g., GRES3001.lnk), disguised as a PDF with a browser-like icon. Upon execution, the shortcut triggers PowerShell via conhost.exe, downloading a decoy PDF while fetching additional malware. To evade detection, the group splits command names (e.g., iw''r instead of iwr) and stores files in common writable directories (C:\Users\Public, C:\Windows\Tasks).
Persistence is established via scheduled tasks (GoogleErrorReport, NewErrorReport), which restart the infection every minute. The original shortcut is then deleted to erase initial attack traces.
The group also abuses DLL side-loading, using legitimate executables (Fondue.exe, VLC) to load malicious components (APPWIZ.cpl, libvlc.dll). These loaders decrypt hidden payloads (e.g., editor.dat, vlc.log) and execute them in memory using the Donut loader, avoiding disk-based detection.
Once active, the RAT disables security features including AMSI, Windows Lockdown Policy, and Event Tracing for Windows to evade scanning and logging. It collects system details, public IP, running processes, and network data, then enables command execution, file exfiltration, screenshots, and process injection via QueueUserAPC.
Patchwork’s adaptive infrastructure and malware updates underscore its persistent espionage focus, blending social engineering, evasion techniques, and multi-stage payloads to maintain access in targeted environments.
Source: https://cyberpress.org/patchwork-apt-expands-espionage/
Turkish Aerospace cybersecurity rating report: https://www.rankiteo.com/company/turkishaerospace
"id": "TUR1786092730",
"linkid": "turkishaerospace",
"type": "Cyber Attack",
"date": "6/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['government',
'defense',
'energy',
'aviation',
'research',
'finance',
'technology',
'pharmaceutical',
'non-profit'],
'location': ['Asia', 'Europe', 'Türkiye', 'U.S.'],
'type': ['government',
'defense',
'energy',
'aviation',
'research',
'finance',
'technology',
'pharmaceutical',
'NGO',
'think tank']}],
'attack_vector': ['phishing',
'malicious shortcuts (.lnk)',
'trojanized Android apps',
'DLL side-loading'],
'data_breach': {'data_exfiltration': True,
'sensitivity_of_data': 'high',
'type_of_data_compromised': ['system details',
'public IP',
'running processes',
'network data',
'messages',
'files',
'call records',
'keystrokes',
'audio',
'images']},
'description': 'The Patchwork APT (also known as Dropping Elephant) continues '
'to refine its tactics against high-value targets, including '
'government, defense, energy, aviation, research, finance, '
'technology, pharmaceutical, NGO, and think tank organizations '
'across Asia, Europe, Türkiye, and the U.S. Recent campaigns '
'demonstrate evolving techniques such as targeted phishing, '
'deceptive document lures, memory-resident malware, and '
'trojanized Android apps. The group deploys fake PDF shortcuts '
'to deliver remote access trojans (RATs) and mobile implants '
'to steal messages, files, call records, keystrokes, audio, '
'and images.',
'impact': {'data_compromised': ['system details',
'public IP',
'running processes',
'network data',
'messages',
'files',
'call records',
'keystrokes',
'audio',
'images'],
'operational_impact': ['command execution',
'file exfiltration',
'screenshots',
'process injection'],
'systems_affected': ['Windows', 'Android']},
'initial_access_broker': {'backdoors_established': ['EyeShell backdoor',
'Brute Ratel C4',
'memory-resident RAT'],
'entry_point': ['phishing', 'malicious shortcuts'],
'high_value_targets': ['Chinese research '
'organizations',
'Bhutan-linked targets',
'Turkish defense '
'contractors']},
'motivation': 'espionage',
'post_incident_analysis': {'root_causes': ['targeted phishing',
'deceptive document lures',
'DLL side-loading',
'memory-resident malware']},
'ransomware': {'data_exfiltration': True},
'references': [{'source': 'Cybersecurity Threat Intelligence Report'}],
'threat_actor': 'Patchwork APT (Dropping Elephant)',
'title': 'Patchwork APT Expands Espionage Operations with Stealthy Malware '
'Tactics',
'type': ['cyber espionage', 'APT campaign']}