A Deep Dive Into Patchwork APT Group
ID: 28b226a1-3a57-5fe4-9919-83dba1c9e21d
STIX ID: report--28b226a1-3a57-5fe4-9919-83dba1c9e21d
Feed Name: Cyble Blog
Threat Score
Cyble researchers describe activity by the Patchwork APT group delivering a custom RAT/keylogger via a malicious Microsoft Word document exploiting CVE-2017-0261; the malware establishes persistence (startup folder and Image File Execution Options), collects system data, logs keystrokes/screenshots, and exfiltrates encrypted data to a hardcoded C2 (176.107.181.213). The report provides SHA-256s, mutex name, exploitation details, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
