Patchwork cyberespionage group expands targets from governments to wide range of industries
ID: d83c9401-e621-4a33-992e-55cf1171f1c2
STIX ID: report--d83c9401-e621-4a33-992e-55cf1171f1c2
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2018-08-10
Last Modified Date: 2018-08-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Patchwork (Dropping Elephant) cyberespionage group expanded from government targets to multiple industries (aviation, energy, finance, NGOs, publishing, software, etc.) across the US, China, Japan, Southeast Asia and the UK, using spear-phishing newsletters linking to tailored websites that deliver malicious .pps and .doc/.rtf files exploiting known Microsoft vulnerabilities to deploy backdoors (Backdoor.Enfourks, Backdoor.Steladok); the report provides exploited CVEs, IoCs (domains, IPs, MD5s), payload details, and mitigation/recommendations.
