Threat Actor 🇮🇳 India
QUILTED TIGER
Also known as: Chinastrats · Patchwork · Monsoon · Sarit · Dropping Elephant · APT-C-09 · ZINC EMERSON · ATK11 · G0040 · Orange Athos · Thirsty Gemini
Dropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and economic targets using a custom set of attack tools. Its victims are all involved with China’s foreign relations in some way, and are generally caught through spear-phishing or watering hole attacks.
Indicators of Compromise 4
MITRE ATT&CK TTPs 125
T1003 T1005 T1021 T1021.001 T1021.002 T1021.003 T1021.004 T1021.005 T1021.006 T1021.007 T1021.008 T1021.009 T1021.010 T1021.011 T1021.012 T1021.013 T1021.014 T1021.015 T1021.016 T1021.017 T1021.018 T1021.019 T1021.020 T1021.021 T1021.022 T1021.023 T1021.024 T1021.025 T1021.026 T1021.027 T1021.028 T1021.029 T1021.030 T1021.031 T1021.032 T1021.033 T1021.034 T1021.035 T1021.036 T1021.037 T1021.038 T1021.039 T1021.040 T1021.041 T1021.042 T1021.043 T1021.044 T1021.045 T1021.046 T1021.047 T1021.048 T1021.049 T1021.050 T1021.051 T1021.052 T1021.053 T1021.054 T1021.055 T1021.056 T1021.057 T1021.058 T1021.059 T1021.060 T1021.061 T1021.062 T1021.063 T1021.064 T1021.065 T1021.066 T1021.067 T1021.068 T1021.069 T1021.070 T1021.071 T1021.072 T1021.073 T1021.074 T1021.075 T1021.076 T1021.077 T1021.078 T1021.079 T1021.080 T1021.081 T1021.082 T1021.083 T1021.084 T1021.085 T1021.086 T1021.087 T1021.088 T1021.089 T1021.090 T1021.091 T1021.092 T1021.093 T1021.094 T1021.095 T1021.096 T1021.097 T1021.098 T1021.099 T1021.100 T1027 T1027.002 T1048 T1053.005 T1055 T1056.001 T1059.001 T1059.005 T1070.004 T1071 T1071.001 T1071.002 T1071.003 T1071.004 T1078 T1082 T1085 T1090 T1095 T1105 T1114.001 T1484.002
OS Credential Dumping
Credential Access
Data from Local System
Collection
Remote Services
Lateral Movement
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Distributed Component Object Model
Lateral Movement
SSH
Lateral Movement
VNC
Lateral Movement
Windows Remote Management
Lateral Movement
Cloud Services
Lateral Movement
Direct Cloud VM Connections
Lateral Movement
T1021.009
T1021.010
T1021.011
T1021.012
T1021.013
T1021.014
T1021.015
T1021.016
T1021.017
T1021.018
T1021.019
T1021.020
T1021.021
T1021.022
T1021.023
T1021.024
T1021.025
T1021.026
T1021.027
T1021.028
T1021.029
T1021.030
T1021.031
T1021.032
T1021.033
T1021.034
T1021.035
T1021.036
T1021.037
T1021.038
T1021.039
T1021.040
T1021.041
T1021.042
T1021.043
T1021.044
T1021.045
T1021.046
T1021.047
T1021.048
T1021.049
T1021.050
T1021.051
T1021.052
T1021.053
T1021.054
T1021.055
T1021.056
T1021.057
T1021.058
T1021.059
T1021.060
T1021.061
T1021.062
T1021.063
T1021.064
T1021.065
T1021.066
T1021.067
T1021.068
T1021.069
T1021.070
T1021.071
T1021.072
T1021.073
T1021.074
T1021.075
T1021.076
T1021.077
T1021.078
T1021.079
T1021.080
T1021.081
T1021.082
T1021.083
T1021.084
T1021.085
T1021.086
T1021.087
T1021.088
T1021.089
T1021.090
T1021.091
T1021.092
T1021.093
T1021.094
T1021.095
T1021.096
T1021.097
T1021.098
T1021.099
T1021.100
Obfuscated Files or Information
Defense Evasion
Software Packing
Defense Evasion
Exfiltration Over Alternative Protocol
Exfiltration
Scheduled Task
Execution
Process Injection
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Visual Basic
Execution
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
File Transfer Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
T1085
Proxy
Command And Control
Non-Application Layer Protocol
Command And Control
Ingress Tool Transfer
Command And Control
Local Email Collection
Collection
Trust Modification
Defense Evasion