🇮🇳Patchwork
🇮🇳 Patchwork is a tracked threat actor in the Clankerusecase corpus. Attributed to IN. Primary motivation: State. We map 26 detection use cases to this actor across 63 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2020-11-13 to 2026-08-06.
crit 1high 1med 2
26Use cases
4Articles
63Techniques
4IOCs
Known aliases
PatchworkDropping ElephantChinastratsQuilted TigerHangover GroupMONSOONOperation Hangover
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.001 · Binary PaddingT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.010 · Command ObfuscationT1033 · System Owner/User DiscoveryT1036.005 · Match Legitimate Resource Name or LocationT1053.005 · Scheduled TaskT1055.012 · Process HollowingT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1074.001 · Local Data StagingT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1098.001 · Additional Cloud CredentialsT1102 · Web ServiceT1102.001 · Dead Drop ResolverT1105 · Ingress Tool TransferT1112 · Modify RegistryT1119 · Automated CollectionT1132.001 · Standard EncodingT1189 · Drive-by CompromiseT1195.002 · Compromise Software Supply ChainT1197 · BITS JobsT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1518.001 · Security Software DiscoveryT1539 · Steal Web Session CookieT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1550.001 · Application Access TokenT1553.002 · Code SigningT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1560 · Archive Collected DataT1562.008 · T1562.008T1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1574.001 · DLLT1574.002 · T1574.002T1587.002 · Code Signing CertificatesT1588.002 · ToolT1598.003 · Spearphishing LinkT1680 · Local Storage Discovery
Detection use cases (26)
Patchwork (Dropping Elephant) weaponized-Office exploit chain → mshta/certutil/PowerShell stager Patchwork BADNEWS dead-drop-resolver C2 from side-loaded / non-browser process Outbound traffic to known AI token-jacking transfer-station infrastructure (Unit42 IPs) Transfer-station client fingerprint: Go-http-client/2.0,gzip(gfe) user-agent in web egress AI resource key creation paired with logging/alert teardown in cloud control plane Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Trusted vendor binary / installer launching unusual children Remote service execution — PsExec / SMB lateral movement AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modulesThreat-intel articles (4)
med Cloud workload security: Mind the gaps · 2026-03-24
Tracked indicators
IP addresses (4)
116.105.166.148 172.96.142.186 3.235.109.125 38.46.219.166