Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
Key Takeaways The advanced persistent threat (APT) group known as Patchwork (or Dropping Elephant) is actively conducting espionage campaigns targeting both Windows and Android users. Attackers...
Key Takeaways
- The advanced persistent threat (APT) group known as Patchwork (or Dropping Elephant) is actively conducting espionage campaigns targeting both Windows and Android users.
- Attackers leverage fake PDF shortcut files to compromise Windows systems and deploy a sophisticated remote access Trojan (RAT).
- For Android devices, the group uses social engineering via romance-themed conversations to lure victims into installing malicious, trojanized chat applications.
- The malware on both platforms is designed for extensive surveillance, including data exfiltration, keystroke logging, and audio/call recording.
- Targets include government, defense, energy, research, aviation, financial, and technology sectors across Asia, Europe, Türkiye, and the United States.
The persistent threat group, known as Patchwork or Dropping Elephant, is executing a dual-platform espionage campaign, utilizing deceptive documents and compromised chat applications to infiltrate both Windows computers and Android smartphones. This sophisticated operation allows the group to siphon sensitive data from a broad spectrum of targets.
Table Of Content
Security researchers at Picus Security said in a report that Patchwork, active since at least 2015, has refined its tactics to include distinct infection chains for each operating system. The group employs a combination of phishing, social engineering, hidden scripts, and mobile surveillance tools to achieve its objectives. Their recent activities highlight a growing trend where threat actors seamlessly transition from desktop compromise to mobile device exploitation, jeopardizing both personal and organizational data.
Windows Systems: Malicious Shortcuts and Persistent Surveillance
The attack on Windows systems begins with a malicious shortcut file, cleverly disguised as a PDF document. One identified example is named “GRES3001.lnk,” designed to appear as an energy contract with a China-related theme. When a user opens this shortcut, it surreptitiously executes a PowerShell downloader via conhost.exe. This process then downloads a benign decoy PDF to display to the victim, while simultaneously retrieving and installing additional malicious components in the background.
To maintain persistence, the malware establishes scheduled tasks, often named “GoogleErrorReport” and “NewErrorReport,” ensuring repeated execution. It also leverages legitimate Windows executables such as Fondue.exe and vlc.exe through DLL side-loading to inject and run its malicious code, a technique previously observed in Patchwork’s operations. The final remote access tool (RAT) is hidden within trusted Windows processes, where it decrypts payloads from local files, loads them into memory, and can even disable or weaken security measures.
Once established, the Windows RAT possesses extensive capabilities, including gathering system information, enumerating files, executing arbitrary commands, capturing screenshots, and exfiltrating selected data to the attackers’ command-and-control (C2) infrastructure. This campaign underscores the critical importance of scrutinizing file extensions, as a PDF icon alone does not guarantee safety. Users and security teams must exercise extreme caution with unexpected attachments.
Android Devices: Romance Lures and Trojanized Chat Apps
For Android targets, Patchwork employs a social engineering strategy centered on romance-themed conversations. Attackers engage victims in chat, eventually persuading them to abandon conventional messaging platforms and install trojanized Android chat applications. These malicious apps are distributed outside official app stores, masquerading as legitimate communication tools while secretly enabling comprehensive surveillance functionalities.
One such identified application, “Wave Chat” (package name com.yoho.talk), grants attackers significant control over the infected device. Its capabilities include reading chat content, logging keystrokes, capturing notifications, stealing contacts and messages, and searching device storage for documents, images, and audio files. Alarmingly, it can also record ambient audio, phone calls, and even calls made through other communication applications, subsequently uploading all captured material to attacker-controlled servers.
The Android implant is designed for resilience, capable of restarting automatically after a device reboot, thereby ensuring continuous data collection without requiring further user interaction. Additional features allow it to capture images using the phone’s camera, collect call records, and selectively delete files, contacts, or call history entries. These extensive surveillance capabilities pose a severe threat, particularly for individuals handling sensitive professional or personal communications.
What You Should Do
- Educate Users: Conduct regular training on phishing, social engineering, and the dangers of opening unexpected attachments, especially those with suspicious file extensions (e.g., LNK files disguised as PDFs).
- Verify File Extensions: Always verify the actual file extension (e.g., .lnk, .exe, .pdf) rather than relying solely on the icon. Enable “Show file extensions” in Windows settings.
- Strict App Sourcing: Only install applications from official and trusted app stores (Google Play Store, Apple App Store). Avoid downloading apps from third-party websites or direct links provided by unknown contacts.
- Review App Permissions: Carefully examine the permissions requested by Android applications before installation. Be wary of chat apps requesting excessive permissions like microphone access, camera control, or extensive file system access.
- Monitor PowerShell Activity: Implement robust monitoring for unusual or unauthorized PowerShell script executions on Windows endpoints.
- Inspect Scheduled Tasks: Regularly review and audit scheduled tasks on Windows systems for any newly created or suspicious entries.
- Network Monitoring: Monitor network traffic for connections to known malicious domains and IP addresses associated with Patchwork (see IoCs below).
- Endpoint Detection and Response (EDR): Utilize EDR solutions to detect and respond to suspicious process activity, DLL side-loading attempts, and unauthorized data exfiltration.
- Incident Response Plan: Ensure your organization has an up-to-date incident response plan ready to address potential compromises of both Windows and Android devices.



No Comment! Be the first one.