logo

Dropping Elephant (Patchwork): Espionage APT Tactics and Tools

ID: 6dd40ca6-9164-56eb-8d49-98da2d36b8ef

STIX ID: report--6dd40ca6-9164-56eb-8d49-98da2d36b8ef

Feed Name: Picus Security Articles

Threat Score
90/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: [email protected] (Umut Bayram)

...
...

**Dropping Elephant (Patchwork)** is an espionage-focused APT active since 2015 that targets government, defense, energy, research, and private-sector organizations across multiple regions using tailored phishing, malicious shortcuts, PowerShell stagers, DLL side‑loading, encrypted shellcode and memory-resident RATs, plus trojanized Android apps that capture messages, calls, keystrokes, images and files. The report catalogs the group's infrastructure, detailed MITRE ATT&CK-mapped TTPs, persistence and evasion techniques, data-exfiltration channels, and example indicators and timelines, and highlights simulation/testing guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.