Patchwork collected and exfiltrated files from the infected system.5
group
Patchwork G0040
- Created
- 31 May 2017
- Last modified
- 31 July 2026
- Aliases
- Patchwork · Hangover Group · Dropping Elephant · Chinastrats · MONSOON · Operation Hangover
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.[1] [2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0040
Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.7
Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.9
Standing G0040
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
77th percentile · 77% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
85th percentile · 85% of 176 ATT&CK groups have this many tactics spanned or fewer.
76th percentile · 76% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
38th percentile · 62% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0040
1415 distinct rules cover the 41 techniques recorded for this group. The 1565 technique-to-rule mappings resolve to 1415 distinct rules, because one rule can cover several techniques. 984 Sigma · 431 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org