INIndiaconfidence: 50G0040G0042

QUILTED TIGERQUILTED TIGER

Also known as: Chinastrats · Patchwork · Monsoon · Sarit · Dropping Elephant · APT-C-09 · ZINC EMERSON · ATK11 · G0040 · Orange Athos · Thirsty Gemini · QUILTED TIGER

Origin
IN
Known aliases
12
Target sectors
2
Attribution
State-sponsored

Profile

Dropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and economic targets using a custom set of attack tools. Its victims are all involved with China’s foreign relations in some way, and are generally caught through spear-phishing or watering hole attacks.

Aliases· 12

ChinastratsPatchworkMonsoonSaritDropping ElephantAPT-C-09ZINC EMERSONATK11Orange AthosThirsty GeminiQUILTED TIGER
G0040

Target sectors· 2

Private sectorMilitary

Known victims· 3

  • Bangladesh
  • Sri Lanka
  • Pakistan

MITRE ATT&CK Group crosswalk

G0040G0042

References

  1. https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=09308982-77bd-41e0-8269-f2cc9ce3266e&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments
  2. https://www.forcepoint.com/blog/x-labs/monsoon-analysis-apt-campaign
  3. https://www.cymmetria.com/patchwork-targeted-attack/
  4. https://s3-us-west-2.amazonaws.com/cymmetria-blog/public/Unveiling_Patchwork.pdf
  5. https://www.volexity.com/blog/2018/06/07/patchwork-apt-group-targets-us-think-tanks/
  6. https://attack.mitre.org/groups/G0040/
  7. https://documents.trendmicro.com/assets/tech-brief-untangling-the-patchwork-cyberespionage-group.pdf
  8. https://securelist.com/the-dropping-elephant-actor/75328/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Fishing Elephant
Actor
APT27
Actor
ModifiedElephant
Actor
MUSTANG PANDA
Actor
RAZOR TIGER
Actor
IndigoZebra
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.