logo

Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent

ID: f7e5c17c-4e0a-4efa-bb30-1751d8c27136

STIX ID: report--f7e5c17c-4e0a-4efa-bb30-1751d8c27136

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2018-04-13

Last Modified Date: 2018-04-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 describes an active Patchwork (Dropping Elephant/Monsoon) campaign targeting Pakistani and regional organizations using weaponized Word documents with embedded EPS exploits (CVE-2015-2545 and CVE-2017-0261) to deploy an updated BADNEWS backdoor. The report covers the delivery chain (EPS exploit → dropped signed VMware executable → malicious DLL side-loading → scheduled task persistence), BADNEWS capabilities (keylogging, file collection, screenshots, dead-drop resolver C2 retrieval and HTTP communications), updated obfuscation/decryption steps, C2 IPs, sample hashes, and scripts to decode dead-drop resolver content.