Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Home/CyberSecurity News/Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
CyberSecurity News

Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android

Key Takeaways The advanced persistent threat (APT) group known as Patchwork (or Dropping Elephant) is actively conducting espionage campaigns targeting both Windows and Android users. Attackers...

Jennifer sherman
Jennifer sherman
August 7, 2026 4 Min Read
2 0

Key Takeaways

  • The advanced persistent threat (APT) group known as Patchwork (or Dropping Elephant) is actively conducting espionage campaigns targeting both Windows and Android users.
  • Attackers leverage fake PDF shortcut files to compromise Windows systems and deploy a sophisticated remote access Trojan (RAT).
  • For Android devices, the group uses social engineering via romance-themed conversations to lure victims into installing malicious, trojanized chat applications.
  • The malware on both platforms is designed for extensive surveillance, including data exfiltration, keystroke logging, and audio/call recording.
  • Targets include government, defense, energy, research, aviation, financial, and technology sectors across Asia, Europe, Türkiye, and the United States.

The persistent threat group, known as Patchwork or Dropping Elephant, is executing a dual-platform espionage campaign, utilizing deceptive documents and compromised chat applications to infiltrate both Windows computers and Android smartphones. This sophisticated operation allows the group to siphon sensitive data from a broad spectrum of targets.

Table Of Content

  • Key Takeaways
  • Windows Systems: Malicious Shortcuts and Persistent Surveillance
  • Android Devices: Romance Lures and Trojanized Chat Apps
  • What You Should Do
  • Indicators of Compromise (IoCs):-

Security researchers at Picus Security said in a report that Patchwork, active since at least 2015, has refined its tactics to include distinct infection chains for each operating system. The group employs a combination of phishing, social engineering, hidden scripts, and mobile surveillance tools to achieve its objectives. Their recent activities highlight a growing trend where threat actors seamlessly transition from desktop compromise to mobile device exploitation, jeopardizing both personal and organizational data.

Windows Systems: Malicious Shortcuts and Persistent Surveillance

The attack on Windows systems begins with a malicious shortcut file, cleverly disguised as a PDF document. One identified example is named “GRES3001.lnk,” designed to appear as an energy contract with a China-related theme. When a user opens this shortcut, it surreptitiously executes a PowerShell downloader via conhost.exe. This process then downloads a benign decoy PDF to display to the victim, while simultaneously retrieving and installing additional malicious components in the background.

To maintain persistence, the malware establishes scheduled tasks, often named “GoogleErrorReport” and “NewErrorReport,” ensuring repeated execution. It also leverages legitimate Windows executables such as Fondue.exe and vlc.exe through DLL side-loading to inject and run its malicious code, a technique previously observed in Patchwork’s operations. The final remote access tool (RAT) is hidden within trusted Windows processes, where it decrypts payloads from local files, loads them into memory, and can even disable or weaken security measures.

Once established, the Windows RAT possesses extensive capabilities, including gathering system information, enumerating files, executing arbitrary commands, capturing screenshots, and exfiltrating selected data to the attackers’ command-and-control (C2) infrastructure. This campaign underscores the critical importance of scrutinizing file extensions, as a PDF icon alone does not guarantee safety. Users and security teams must exercise extreme caution with unexpected attachments.

Android Devices: Romance Lures and Trojanized Chat Apps

For Android targets, Patchwork employs a social engineering strategy centered on romance-themed conversations. Attackers engage victims in chat, eventually persuading them to abandon conventional messaging platforms and install trojanized Android chat applications. These malicious apps are distributed outside official app stores, masquerading as legitimate communication tools while secretly enabling comprehensive surveillance functionalities.

One such identified application, “Wave Chat” (package name com.yoho.talk), grants attackers significant control over the infected device. Its capabilities include reading chat content, logging keystrokes, capturing notifications, stealing contacts and messages, and searching device storage for documents, images, and audio files. Alarmingly, it can also record ambient audio, phone calls, and even calls made through other communication applications, subsequently uploading all captured material to attacker-controlled servers.

The Android implant is designed for resilience, capable of restarting automatically after a device reboot, thereby ensuring continuous data collection without requiring further user interaction. Additional features allow it to capture images using the phone’s camera, collect call records, and selectively delete files, contacts, or call history entries. These extensive surveillance capabilities pose a severe threat, particularly for individuals handling sensitive professional or personal communications.

What You Should Do

  • Educate Users: Conduct regular training on phishing, social engineering, and the dangers of opening unexpected attachments, especially those with suspicious file extensions (e.g., LNK files disguised as PDFs).
  • Verify File Extensions: Always verify the actual file extension (e.g., .lnk, .exe, .pdf) rather than relying solely on the icon. Enable “Show file extensions” in Windows settings.
  • Strict App Sourcing: Only install applications from official and trusted app stores (Google Play Store, Apple App Store). Avoid downloading apps from third-party websites or direct links provided by unknown contacts.
  • Review App Permissions: Carefully examine the permissions requested by Android applications before installation. Be wary of chat apps requesting excessive permissions like microphone access, camera control, or extensive file system access.
  • Monitor PowerShell Activity: Implement robust monitoring for unusual or unauthorized PowerShell script executions on Windows endpoints.
  • Inspect Scheduled Tasks: Regularly review and audit scheduled tasks on Windows systems for any newly created or suspicious entries.
  • Network Monitoring: Monitor network traffic for connections to known malicious domains and IP addresses associated with Patchwork (see IoCs below).
  • Endpoint Detection and Response (EDR): Utilize EDR solutions to detect and respond to suspicious process activity, DLL side-loading attempts, and unauthorized data exfiltration.
  • Incident Response Plan: Ensure your organization has an up-to-date incident response plan ready to address potential compromises of both Windows and Android devices.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain expouav[.]org Delivery domain used to host Patchwork payloads.
Domain roseserve[.]org Command-and-control domain used in a Türkiye-focused operation. <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/6784b167-0488-45be-b902-29daf99525fd/Fake-PDFs-and-Chat-Apps-Let-Patchwork-Spy-on-PCs-and-Android-Phones.pdf?AWSAccessKeyId=ASIA2F3EMEYE53UZ4JJF&Signature=7nbqvVgNwufXw%2FqyQ%2B8sKASvf%2Bk%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCnS7UZDKJs96PgvUJCdsa0Nl9%2FR%2F5mpGg8QaoDjctsLAIhAINyPgDW89QQ27kBlQFI0t22wejtl5gAQmkFHAutK%2BYiKvMECFQQARoMNjk5NzUzMzA5NzA1IgyEFn9lY%2FUYq0wstsEq0ASdZqtk7gw%2B4%2B8gyQDIrgmBumB84cCD8BZQYG64DG8sNyr6gWdK2TvdukRsIAkc7GluYyP%2BPCZH8wiODS2suuFqAWCMGoTBhNUJh%2BWseQYq5js3Whs5KwQlLCKOhK2Y2LVZko8TWF5GO%2FXkf%2BGEhlFfjFtSKiL5XMkFNPOSjuG7s3d3EXH1jkHW5%2FmJfeTANAncV56QxOvSqXEH5tz0jbaPAnz5WLDiL2cojHp2DRFRbzOEcDz6iSabyfQGhhtiLgjiMLhCAsS2dDPeBzNmj5FDHW6baUuR9dnMYnRG79eulrqo%2F6fhyWFL1M4t00cZeY7pKn1JwuoADc4t0rn0DDyxLsUHwTltva2Klgc6u1g7WKzZ7n1xya4FWwomkqHI3kVSscpO7u8KFlpvZYvHwwzIIUlv73q1v1cdrYqY%2FRqdVOp4f5ZHkNDv4CBdLyy4jhh16sJVPeThV%2BPfQ4S4rmKRYwKSBhUeWAL16GpJ3Ld%2FrMWuazFq6%2B1jyGLTvakDO5ZcucMMIdN8eb%2BXzDdwYgslIyB979IEDPY5Ojl%2FBM6k5xOg5JNJGR9DMjSqwidpFjxIwS4MDsFtwcXD%2FHqOFCr1780DYmW3PVQFjP4RHzhxOyTH

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchphishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts

Next Post

Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ChainDrop Worm Steals GitHub, Cloud Credentials via 400+ npm Packages
August 7, 2026
UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
August 7, 2026
Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us