The cyber espionage group known as Patchwork, also referred to as Dropping Elephant, has been identified employing deceptive tactics to infiltrate both Windows computers and Android smartphones. By leveraging fake documents and chat applications, the group aims to extract sensitive information from targeted devices.
Windows Infiltration via Fake PDFs
On Windows systems, Patchwork initiates its attack through a malicious shortcut file disguised as a PDF document. When the user opens this file, it triggers a hidden PowerShell script that downloads and displays a decoy PDF to maintain the illusion of legitimacy. Simultaneously, the script installs malware in the background without the user’s knowledge.
To ensure persistence, the malware creates scheduled tasks named ‘GoogleErrorReport’ and ‘NewErrorReport,’ which execute at regular intervals. Additionally, it exploits legitimate-looking files, such as ‘Fondue.exe’ and ‘vlc.exe,’ to load malicious code, thereby evading detection. Once established, the malware can collect system details, list files, execute commands, capture screenshots, and transmit selected data back to its operators.
Android Compromise via Trojanized Chat Apps
For Android devices, Patchwork employs social engineering tactics by engaging targets in romance-themed conversations. The attackers persuade victims to move their chats from standard messaging platforms to malicious chat applications distributed outside official app stores. These trojanized apps appear functional but operate surveillance tools in the background.
One such application, ‘Wave Chat,’ has been identified with capabilities to read chat content, log keystrokes, collect notifications, steal contacts and messages, and search device storage for various files. It can also record ambient sounds, phone calls, and calls made through other communication apps, subsequently uploading the captured data to servers controlled by the attackers. The malware ensures persistence by restarting after device reboots and can perform actions like capturing images via the device’s camera, gathering call records, and deleting specific files, contacts, or call-history entries.
These sophisticated methods highlight the evolving strategies of cyber espionage groups like Patchwork. Users are advised to exercise caution when handling unexpected attachments, especially those that appear as PDFs but have ‘.lnk’ extensions. It’s crucial to install applications only from trusted sources, scrutinize permission requests, and be wary of moving conversations to unfamiliar chat apps, particularly when prompted by unknown contacts. Organizations should enhance their security measures to detect suspicious activities, such as unusual PowerShell executions, malicious shortcut files, and unauthorized Android applications, to mitigate the risks posed by such advanced threats.