logo

Patchwork cyberespionage group expands targets from governments to wide range of industries

ID: d83c9401-e621-4a33-992e-55cf1171f1c2

STIX ID: report--d83c9401-e621-4a33-992e-55cf1171f1c2

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2018-08-10

Last Modified Date: 2018-08-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Patchwork (Dropping Elephant) cyberespionage group expanded from government targets to multiple industries (aviation, energy, finance, NGOs, publishing, software, etc.) across the US, China, Japan, Southeast Asia and the UK, using spear-phishing newsletters linking to tailored websites that deliver malicious .pps and .doc/.rtf files exploiting known Microsoft vulnerabilities to deploy backdoors (Backdoor.Enfourks, Backdoor.Steladok); the report provides exploited CVEs, IoCs (domains, IPs, MD5s), payload details, and mitigation/recommendations.