logo

Patchwork APT Group Targets US Think Tanks

ID: cc16a21b-1c26-593e-85e3-23499f03798c

STIX ID: report--cc16a21b-1c26-593e-85e3-23499f03798c

Feed Name: Volexity Blog

Threat Score
72/100

Date Published: 2018-06-07

Date Updated: 2026-05-01

...
...

Volexity observed Patchwork spear-phishing campaigns in Mar–Apr 2018 that impersonated US think tanks (CFR, CSIS, MERICS) and used tracking images to identify recipients; malicious RTF attachments exploited CVE-2017-8570 (public PoC) to drop QuasarRAT and other RATs, establish persistence via scheduled tasks, and beacon to identified C2 domains/IPs. The report provides exploitation details, sample files and hashes, network indicators, and analysis of the actors' tradecraft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.