logo

A Deep Dive Into Patchwork APT Group

ID: 28b226a1-3a57-5fe4-9919-83dba1c9e21d

STIX ID: report--28b226a1-3a57-5fe4-9919-83dba1c9e21d

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-09

Date Updated: 2026-07-16

...
...

Cyble researchers describe activity by the Patchwork APT group delivering a custom RAT/keylogger via a malicious Microsoft Word document exploiting CVE-2017-0261; the malware establishes persistence (startup folder and Image File Execution Options), collects system data, logs keystrokes/screenshots, and exfiltrates encrypted data to a hardcoded C2 (176.107.181.213). The report provides SHA-256s, mutex name, exploitation details, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.