Overview

This report highlights two distinct India-linked threat groups, Patchwork and Bitter Elephant. It outlines practical approaches for analyzing and tracking their operations using ANY.RUN’s solutions, including behavioral analysis in the sandbox and contextual enrichment through TI Lookup. The report provides relevant IOCs, TTPs, adversary profiles, and supporting technical context for each case, aiming to enhance threat hunting and attribution efforts across related campaigns.


🚨 Patchwork activity

A recent post by the RedDrip Team reported activity attributed to the Patchwork APT group involving malicious .lnk shortcut files in the initial stage.

Threat Actor Profile: Patchwork

Patchwork is an advanced persistent threat group suspected to be operating from India. Active since at least 2009, Patchwork is known for targeting organizations across Asia, primarily for espionage purposes.

  • Origin: India

  • Active Since: 2009

  • Motivation: Espionage

  • Targeted Countries: Nepal, United States, China, Pakistan, Taiwan, Malaysia, Sri Lanka, Uruguay, Bangladesh, Australia, Turkey

  • Targeted Industries: Aviation, Defense, Energy, Finance, Government, Information Technology, Media, NGOs, Pharmaceuticals, Education

Analysis of Related activity in ANY.RUN

We can analyze the .lnk sample submitted to the ANY.RUN sandbox to examine its behavior in detail and uncover additional indicators.

  • SHA-256: 2f329a1171d2c6b1471604bf76157b6487c3e59d21bf4a0856e29dc4ba8753cb

  • Sample: ANY.RUN

1lnk_patchwork

We observed that upon execution of the .lnk file, an obfuscated PowerShell command is launched, which downloads a payload from hxxps[:]//nr3cgovpk.org/download/fetch/list1/25807/view/ and establishes persistence by creating a scheduled task named WindowsErrorReport.

powrshell_loader

We can search for related tasks by matching command lines that contain parts of the URL used to download the payload.

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: commandLine:"/download/fetch/list*/view*"

We can also refine the search parameters based on the recurring command patterns observed in the first stage, to filter out cases where only malicious URLs were analyzed.

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: commandLine:"*powershell*SilentlyContinue*http*/list*minute"

Executing the query surfaced sandbox samples matching the pattern observed in malicious PowerShell commands. Analysis of those runs/tasks revealed additional related domains used to deliver second-stage payloads, enriching our IOC set.

The domains identified in the most recent analyses were found to mimic websites of Pakistani government organizations, as well as Turkish defense and educational institutions. In earlier activity, some domains were observed impersonating Chinese educational organizations.

  • asiapacifictelecommunity[.]com
  • swo-pakistan[.]org
  • nr3cgovpk[.]org
  • documents.nrtc-com-pk[.]org
  • doc.nrtc-com-pk[.]org
  • etu-edu[.]org
  • stm-tr[.]org
  • expouav[.]org
  • mkek-govtr[.]com
  • jlu-edu[.]org

patchworkfirstlookup

During analysis we also observed a variant where the first-stage payload was an .msc file — NRTC_Company_Profile.pdf.msc — disguised as a PDF and impersonating a document from the National Radio Telecommunication Corporation (Pakistan). This sample contacted the resource frieagenter[.]net.

  • Analysis: ANY.RUN

NRTC_Company_Profile.pdf.msc

  • SHA-256: af4fc51ef488817de5176795543d31d7a2b03250f7ced0c188c44a7a1fcad622

We also identified another malicious .msc file RFQ_Tactical_UAV_Systems_POF.pdf.msc that connects to frieagenter[.]net.

  • SHA-256: 89cd843d7b71d717c73f1631488be68a64f8563599109350bd7105fbf13fa450

  • Sample: ANY.RUN

It appears these .msc files exploit the vulnerability described as GrimResource - opening a specially crafted .msc results in execution of malicious code.

🚨 Bitter Elephant activity

A recent post on X reported activity attributed to the Bitter Elephant APT group.

Threat Actor Profile: Bitter Elephant

Bitter Elephant is a cyber espionage group linked to India, active since at least 2013, targeting government and defense organizations across Asia and the Middle East.

  • Origin: India

  • Active Since: 2013

  • Motivation: Information Theft, Espionage

  • Targeted Countries: Saudi Arabia, Turkey, Bangladesh, China, Pakistan, South Korea

  • Targeted Industries: Government, Energy, Engineering, Defense, Telecommunications

Analysis of Related activity in ANY.RUN

The .chm file observed on ANY.RUN employs a double extension to disguise itself as a PDF document.

  • SHA-256: 624decbc0445e51873436e42699323bf48093e0c4ba5ea1d348e9e5a1822579b

  • Sample: ANY.RUN

After the .chm is opened, it launches conhost.exe --headless, a commonly observed LOLBin abuse, which executes the following malicious command:

bitterelephantcmd

This command creates a scheduled task named OneDriveLogon, fetches a payload from seragoonupdates.com/nvxq.php, and saving as C:\ProgramData\jd.yv, and then pipes the downloaded content to cmd for execution.

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: commandLine:"*conhost.exe*--headless cmd*schtasks*.php*"

During the analysis, two additional .chm files were identified. When opened, each executed a single conhost.exe --headless command following the same pattern as the original sample - creating a scheduled task and contacting a remote .php script. Although task names and domains varied, the overall command structure remained consistent.

  • SHA-256: a1371bff74566cf0d693311699334165093749071c9a1868784b1e99210cdad0

  • Sample: ANY.RUN

cmd2

  • SHA-256: 8af2d392181c359ce04e38ab113e22e526eae4c6f715d26462e439a3db1eb948

  • Sample: ANY.RUN

cmd3

In the recently identified sample, a ping command is executed, no obfuscation is used, and the connection to the remote script is made via Invoke-RestMethod.

The samples identified via the TI lookup were previously observed in a sandbox during earlier attack campaigns and employ command-line obfuscation; they contact remote servers using curl, and one sample deliberately emits a fabricated error message - most likely noise or an attempt to disguise the malicious activity.

Conclusion

The report presents two case studies of recent operations attributed to Patchwork and Bitter Elephant, focusing on their technical patterns and artifacts. It demonstrates how ANY.RUN’s ecosystem can be used to trace such activities, connect related samples, and enrich investigations through sandbox telemetry and threat intelligence correlation. The findings contribute to a deeper understanding of these India-linked actors and support more effective detection and response to similar threats.