This report highlights two distinct India-linked threat groups, Patchwork and Bitter Elephant. It outlines practical approaches for analyzing and tracking their operations using ANY.RUN’s solutions, including behavioral analysis in the sandbox and contextual enrichment through TI Lookup. The report provides relevant IOCs, TTPs, adversary profiles, and supporting technical context for each case, aiming to enhance threat hunting and attribution efforts across related campaigns.
A recent post by the RedDrip Team reported activity attributed to the Patchwork APT group involving malicious .lnk shortcut files in the initial stage.
Patchwork is an advanced persistent threat group suspected to be operating from India. Active since at least 2009, Patchwork is known for targeting organizations across Asia, primarily for espionage purposes.
Origin: India
Active Since: 2009
Motivation: Espionage
Targeted Countries: Nepal, United States, China, Pakistan, Taiwan, Malaysia, Sri Lanka, Uruguay, Bangladesh, Australia, Turkey
Targeted Industries: Aviation, Defense, Energy, Finance, Government, Information Technology, Media, NGOs, Pharmaceuticals, Education
We can analyze the .lnk sample submitted to the ANY.RUN sandbox to examine its behavior in detail and uncover additional indicators.
SHA-256: 2f329a1171d2c6b1471604bf76157b6487c3e59d21bf4a0856e29dc4ba8753cb
Sample: ANY.RUN

We observed that upon execution of the .lnk file, an obfuscated PowerShell command is launched, which downloads a payload from hxxps[:]//nr3cgovpk.org/download/fetch/list1/25807/view/ and establishes persistence by creating a scheduled task named WindowsErrorReport.

We can search for related tasks by matching command lines that contain parts of the URL used to download the payload.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"/download/fetch/list*/view*"
We can also refine the search parameters based on the recurring command patterns observed in the first stage, to filter out cases where only malicious URLs were analyzed.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"*powershell*SilentlyContinue*http*/list*minute"
Executing the query surfaced sandbox samples matching the pattern observed in malicious PowerShell commands. Analysis of those runs/tasks revealed additional related domains used to deliver second-stage payloads, enriching our IOC set.
The domains identified in the most recent analyses were found to mimic websites of Pakistani government organizations, as well as Turkish defense and educational institutions. In earlier activity, some domains were observed impersonating Chinese educational organizations.
asiapacifictelecommunity[.]comswo-pakistan[.]orgnr3cgovpk[.]orgdocuments.nrtc-com-pk[.]orgdoc.nrtc-com-pk[.]orgetu-edu[.]orgstm-tr[.]orgexpouav[.]orgmkek-govtr[.]comjlu-edu[.]org
During analysis we also observed a variant where the first-stage payload was an .msc file — NRTC_Company_Profile.pdf.msc — disguised as a PDF and impersonating a document from the National Radio Telecommunication Corporation (Pakistan). This sample contacted the resource frieagenter[.]net.
NRTC_Company_Profile.pdf.msc
af4fc51ef488817de5176795543d31d7a2b03250f7ced0c188c44a7a1fcad622We also identified another malicious .msc file RFQ_Tactical_UAV_Systems_POF.pdf.msc that connects to frieagenter[.]net.
SHA-256: 89cd843d7b71d717c73f1631488be68a64f8563599109350bd7105fbf13fa450
Sample: ANY.RUN
It appears these .msc files exploit the vulnerability described as GrimResource - opening a specially crafted .msc results in execution of malicious code.
A recent post on X reported activity attributed to the Bitter Elephant APT group.
Bitter Elephant is a cyber espionage group linked to India, active since at least 2013, targeting government and defense organizations across Asia and the Middle East.
Origin: India
Active Since: 2013
Motivation: Information Theft, Espionage
Targeted Countries: Saudi Arabia, Turkey, Bangladesh, China, Pakistan, South Korea
Targeted Industries: Government, Energy, Engineering, Defense, Telecommunications
The .chm file observed on ANY.RUN employs a double extension to disguise itself as a PDF document.
SHA-256: 624decbc0445e51873436e42699323bf48093e0c4ba5ea1d348e9e5a1822579b
Sample: ANY.RUN
After the .chm is opened, it launches conhost.exe --headless, a commonly observed LOLBin abuse, which executes the following malicious command:

This command creates a scheduled task named OneDriveLogon, fetches a payload from seragoonupdates.com/nvxq.php, and saving as C:\ProgramData\jd.yv, and then pipes the downloaded content to cmd for execution.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"*conhost.exe*--headless cmd*schtasks*.php*"
During the analysis, two additional .chm files were identified. When opened, each executed a single conhost.exe --headless command following the same pattern as the original sample - creating a scheduled task and contacting a remote .php script. Although task names and domains varied, the overall command structure remained consistent.
SHA-256: a1371bff74566cf0d693311699334165093749071c9a1868784b1e99210cdad0
Sample: ANY.RUN

SHA-256: 8af2d392181c359ce04e38ab113e22e526eae4c6f715d26462e439a3db1eb948
Sample: ANY.RUN

In the recently identified sample, a ping command is executed, no obfuscation is used, and the connection to the remote script is made via Invoke-RestMethod.
The samples identified via the TI lookup were previously observed in a sandbox during earlier attack campaigns and employ command-line obfuscation; they contact remote servers using curl, and one sample deliberately emits a fabricated error message - most likely noise or an attempt to disguise the malicious activity.
The report presents two case studies of recent operations attributed to Patchwork and Bitter Elephant, focusing on their technical patterns and artifacts. It demonstrates how ANY.RUN’s ecosystem can be used to trace such activities, connect related samples, and enrich investigations through sandbox telemetry and threat intelligence correlation. The findings contribute to a deeper understanding of these India-linked actors and support more effective detection and response to similar threats.