logo

The Dropping Elephant – aggressive cyber-espionage in the Asian region

ID: 480ade32-8b51-453c-9f17-e13e3754f0a1

STIX ID: report--480ade32-8b51-453c-9f17-e13e3754f0a1

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2016-07-17

Last Modified Date: 2016-07-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky's analysis of the Dropping Elephant/Chinastrats (Patchwork) campaign describes a targeted cyber-espionage operation focused on diplomatic and China-related targets in Asia using spear-phishing and watering-hole vectors. Attackers leveraged legacy MS Office exploits (e.g., CVE-2012-0158, CVE-2014-6352/1761), AutoIt-packed backdoors that fetch PowerShell-encoded stages, and file-stealer modules to exfiltrate Office/PDF documents; the report includes C2 behavior analysis, logon activity, geolocation observations and a comprehensive set of IoCs (file hashes, malicious document names, domains and IPs) to aid detection and remediation.