The Dropping Elephant – aggressive cyber-espionage in the Asian region
ID: 480ade32-8b51-453c-9f17-e13e3754f0a1
STIX ID: report--480ade32-8b51-453c-9f17-e13e3754f0a1
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2016-07-17
Last Modified Date: 2016-07-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky's analysis of the Dropping Elephant/Chinastrats (Patchwork) campaign describes a targeted cyber-espionage operation focused on diplomatic and China-related targets in Asia using spear-phishing and watering-hole vectors. Attackers leveraged legacy MS Office exploits (e.g., CVE-2012-0158, CVE-2014-6352/1761), AutoIt-packed backdoors that fetch PowerShell-encoded stages, and file-stealer modules to exfiltrate Office/PDF documents; the report includes C2 behavior analysis, logon activity, geolocation observations and a comprehensive set of IoCs (file hashes, malicious document names, domains and IPs) to aid detection and remediation.
