ATT&CKGroupsPatchwork

Patchwork

G0040

Threat group.View on attack.mitre.org

About this group

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.

Techniques used41

Procedure examples41

TechniqueProcedure example
T1005
Data from Local System

Patchwork collected and exfiltrated files from the infected system.

T1021.001
Remote Desktop Protocol

Patchwork attempted to use RDP to move laterally.

T1027.001
Binary Padding

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.002
Software Packing

A Patchwork payload was packed with UPX.

T1027.005
Indicator Removal from Tools

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.010
Command Obfuscation

Patchwork has obfuscated a script with Crypto Obfuscator.

T1033
System Owner/User Discovery

Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server.

T1036.005
Match Legitimate Resource Name or Location

Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.

T1053.005
Scheduled Task

A Patchwork file stealer can run a TaskScheduler DLL to add persistence.

T1055.012
Process Hollowing

A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe.

T1059.001
PowerShell

Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine.

T1059.003
Windows Command Shell

Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines.

T1059.005
Visual Basic

Patchwork used Visual Basic Scripts (VBS) on victim machines.

T1070.004
File Deletion

Patchwork removed certain files and replaced them so they could not be retrieved.

T1074.001
Local Data Staging

Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server.

View all 41 procedure examples

Software8

Campaigns0

None recorded.

References4

  1. Cymmetria Patchwork Open source
    Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.
  2. Symantec Patchwork Open source
    Hamada, J.. (2016, July 25). Patchwork cyberespionage group expands targets from governments to wide range of industries. Retrieved August 17, 2016.
  3. TrendMicro Patchwork Dec 2017 Open source
    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.
  4. Volexity Patchwork June 2018 Open source
    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.