DROPPING ELEPHANT
CHINASTRATS
QUILTED TIGER
MONSOON
Threat IntelligenceAPTJanuary 27, 202615 min read

Patchwork: Threat Intelligence Profile

Indian-linked APT targeting Pakistan and China with copy-paste code from multiple sources, known for occasionally infecting their own systems with their own malware.

Scroll

Patchwork / Dropping Elephant (also known as Dropping Elephant, Chinastrats, Quilted Tiger, Monsoon) is a state-sponsored advanced persistent threat group attributed to India (suspected), active since 2015. The group primarily targets Pakistan, China government, diplomatic entities sectors. It is tracked by MITRE ATT&CK as G0040.

Overview & Attribution

Indian-linked APT targeting Pakistan and China with copy-paste code from multiple sources, known for occasionally infecting their own systems with their own malware.

Threat Assessment

Patchwork has been active since 2015, attributed to India (suspected). The group is known for targeting Pakistan, China government, diplomatic entities using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

Patchwork employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on Pakistan, China government, diplomatic entities sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

Patchwork is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentSpearphishing with RTF exploits
ExecutionT1203 Exploitation for Client ExecutionOffice vulnerability exploitation
PersistenceT1547.001 Registry Run KeysRegistry persistence
CollectionT1056.001 KeyloggingKeystroke capture
CollectionT1113 Screen CaptureScreenshot collection
C2T1071.001 Web ProtocolsHTTP C2

Notable Campaigns

Patchwork has been linked to multiple significant campaigns targeting Pakistan, China government, diplomatic entities organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against Patchwork

Mjolnir Security provides specialized capabilities to detect and respond to Patchwork operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for Patchwork TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of Patchwork campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: January 27, 2026