← Back to Daily Briefing

Dropping Elephant, also known as Patchwork, is a persistent espionage-focused APT active since late 2015. The actor employs a dual-platform attack strategy targeting high-value sectors including defense, energy, and government across Asia, Europe, Türkiye, and the United States. On Windows, the group utilizes malicious .lnk files disguised as PDF documents to execute obfuscated PowerShell downloaders and staged payloads. Simultaneously, the threat actor deploys trojanized Android applications via social engineering and romance-themed lures. These mobile payloads facilitate extensive data exfiltration, including keystroke logging, call recording, and message interception, enabling long-term intelligence gathering and organizational espionage.

  • Campaign Overview & Strategic Intent
    • Long-term espionage-driven operations active since at least December 2015.
    • Geographic focus centers on the United States, Türkiye, Europe, and Asia.
    • Primary objective involves persistent intelligence gathering against high-interest organizational targets.
  • Windows Attack Vector & Execution
    • Deployment of malicious .lnk (shortcut) files masquerading as PDF documents.
    • Execution of obfuscated PowerShell downloaders to retrieve and run secondary payloads.
    • Implementation of staged payloads and persistence mechanisms to maintain unauthorized host access.
  • Android Mobile Exploitation
    • Distribution of trojanized Android applications via romance-themed social engineering lures.
    • Advanced mobile payload capabilities including keystroke logging and call recording.
    • Systematic exfiltration of sensitive data, including SMS messages, images, and local files.
  • Targeted Sectors & Impact Scope
    • High-priority targets include Government, Defense, Energy, Aviation, and Research sectors.
    • Secondary interest in Financial, Technology, Pharmaceutical, and NGO/Think Tank organizations.
    • Broad impact ranging from organizational infrastructure to individual high-value personnel.
  • Defensive Posture & Detection
    • Monitor endpoints for anomalous .lnk file executions and unauthorized PowerShell activity.
    • Enforce strict Mobile Device Management (MDM) to mitigate unapproved application installations.
    • Conduct advanced social engineering training focused on evolving multi-platform lures.
  • Conclusion
    • The actor demonstrates significant maturity in executing cross-platform attack orchestration.
    • Adaptive defense-in-depth is required to counter evolving social engineering and mobile threats.

Related posts

  1. Malware News — Dropping Elephant (Patchwork): Espionage APT Tactics and Tools
  2. Docs
  3. Securelist
  4. Trendmicro
  5. Welivesecurity
  6. Arcticwolf
  7. Rapid7
  8. Malpedia
  9. Apt
  10. Vulncheck
  11. Brandefense
  12. Socradar

LINK COPIED TO CLIPBOARD