logo

QUILTED_TIGER__2022__Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs.pdf

ID: 1cb407b6-8cf5-47b4-af5f-61704dfaeb72

STIX ID: report--1cb407b6-8cf5-47b4-af5f-61704dfaeb72

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2022-01-09

Last Modified Date: 2022-01-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Malwarebytes Labs reports that the Patchwork APT deployed a new BADNEWS/Ragnatela RAT via malicious RTF spearphishes targeting Pakistani government and biological-research institutions; the RAT provides command execution, keylogging, screenshots, file listing/transfers and downloads additional payloads. The actor’s operational mistakes (self-infection) exposed screenshots, keystrokes, PDB/source-path artifacts and testing evidence; the report provides IoCs including the lure (karachidha.org/docs/EOIForm.rtf), RAT filename/hash (jii.dll / 3d3598d3...), and C2 bgre.kozow.com.