← Back to all threat actors

Patchwork

Also known as Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover
Tracked as G0040

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G0040

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Hangover Group

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Dropping Elephant

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Chinastrats

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: MONSOON

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Operation Hangover

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

PatchworkCanonical Name
ChinastratsAlias
Dropping ElephantAlias
Hangover GroupAlias
MONSOONAlias
Operation HangoverAlias
G0040Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...