Threat Actor 🇮🇳 India

QUILTED TIGER

Also known as: Chinastrats · Patchwork · Monsoon · Sarit · Dropping Elephant · APT-C-09 · ZINC EMERSON · ATK11 · G0040 · Orange Athos · Thirsty Gemini

Dropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and economic targets using a custom set of attack tools. Its victims are all involved with China’s foreign relations in some way, and are generally caught through spear-phishing or watering hole attacks.

Indicators of Compromise 4

MITRE ATT&CK TTPs 125

T1003
OS Credential Dumping
Credential Access
T1005
Data from Local System
Collection
T1021
Remote Services
Lateral Movement
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1021.003
Distributed Component Object Model
Lateral Movement
T1021.004
SSH
Lateral Movement
T1021.005
VNC
Lateral Movement
T1021.006
Windows Remote Management
Lateral Movement
T1021.007
Cloud Services
Lateral Movement
T1021.008
Direct Cloud VM Connections
Lateral Movement
T1021.009
T1021.009
T1021.010
T1021.010
T1021.011
T1021.011
T1021.012
T1021.012
T1021.013
T1021.013
T1021.014
T1021.014
T1021.015
T1021.015
T1021.016
T1021.016
T1021.017
T1021.017
T1021.018
T1021.018
T1021.019
T1021.019
T1021.020
T1021.020
T1021.021
T1021.021
T1021.022
T1021.022
T1021.023
T1021.023
T1021.024
T1021.024
T1021.025
T1021.025
T1021.026
T1021.026
T1021.027
T1021.027
T1021.028
T1021.028
T1021.029
T1021.029
T1021.030
T1021.030
T1021.031
T1021.031
T1021.032
T1021.032
T1021.033
T1021.033
T1021.034
T1021.034
T1021.035
T1021.035
T1021.036
T1021.036
T1021.037
T1021.037
T1021.038
T1021.038
T1021.039
T1021.039
T1021.040
T1021.040
T1021.041
T1021.041
T1021.042
T1021.042
T1021.043
T1021.043
T1021.044
T1021.044
T1021.045
T1021.045
T1021.046
T1021.046
T1021.047
T1021.047
T1021.048
T1021.048
T1021.049
T1021.049
T1021.050
T1021.050
T1021.051
T1021.051
T1021.052
T1021.052
T1021.053
T1021.053
T1021.054
T1021.054
T1021.055
T1021.055
T1021.056
T1021.056
T1021.057
T1021.057
T1021.058
T1021.058
T1021.059
T1021.059
T1021.060
T1021.060
T1021.061
T1021.061
T1021.062
T1021.062
T1021.063
T1021.063
T1021.064
T1021.064
T1021.065
T1021.065
T1021.066
T1021.066
T1021.067
T1021.067
T1021.068
T1021.068
T1021.069
T1021.069
T1021.070
T1021.070
T1021.071
T1021.071
T1021.072
T1021.072
T1021.073
T1021.073
T1021.074
T1021.074
T1021.075
T1021.075
T1021.076
T1021.076
T1021.077
T1021.077
T1021.078
T1021.078
T1021.079
T1021.079
T1021.080
T1021.080
T1021.081
T1021.081
T1021.082
T1021.082
T1021.083
T1021.083
T1021.084
T1021.084
T1021.085
T1021.085
T1021.086
T1021.086
T1021.087
T1021.087
T1021.088
T1021.088
T1021.089
T1021.089
T1021.090
T1021.090
T1021.091
T1021.091
T1021.092
T1021.092
T1021.093
T1021.093
T1021.094
T1021.094
T1021.095
T1021.095
T1021.096
T1021.096
T1021.097
T1021.097
T1021.098
T1021.098
T1021.099
T1021.099
T1021.100
T1021.100
T1027
Obfuscated Files or Information
Defense Evasion
T1027.002
Software Packing
Defense Evasion
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1056.001
Keylogging
Collection
T1059.001
PowerShell
Execution
T1059.005
Visual Basic
Execution
T1070.004
File Deletion
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1071.002
File Transfer Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1071.004
DNS
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1085
T1085
T1090
Proxy
Command And Control
T1095
Non-Application Layer Protocol
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1114.001
Local Email Collection
Collection
T1484.002
Trust Modification
Defense Evasion

Source Articles