Patchwork
Also known as: apt-c-09, atk11, chinastrats, dropping elephant, g0040, hangover group, monsoon, operation hangover, orange athos, quilted tiger, sarit, thirsty gemini
[Patchwork](https://attack.mitre.org/groups/G0040) is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. [Patchwork](https://attack.mitre.org/groups/G0040) has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. [Patchwork](https://attack.mitre.org/groups/G0040) was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.(Citation: Cymmetria Patchwork) (Citation: Symantec Patchwork)(Citation: TrendMicro Patchwork Dec 2017)(Citation: Volexity Patchwork June 2018)
Most affected countries
No data yet.
Most affected sectors
No data yet.
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- User Training (7 techniques covered)
- Restrict Web-Based Content (7 techniques covered)
- Audit (7 techniques covered)
- User Account Management (6 techniques covered)
- Execution Prevention (6 techniques covered)
- Network Intrusion Prevention (5 techniques covered)
- Behavior Prevention on Endpoint (5 techniques covered)
- Antivirus/Antimalware (5 techniques covered)
MITRE ATT&CK techniques
Recent victims
No data yet.
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.