QUILTED TIGER is an India-linked nation-state APT group known for Spearphishing attacks targeting military and diplomatic entities.
Analyst brief
QUILTED TIGER (aka Patchwork, Dropping Elephant) is a nation-state actor originating from India. It targets military, financial, diplomatic, and private-sector entities in Bangladesh, Sri Lanka, and Pakistan, focusing on those involved with China's foreign relations. Key TTPs include initial access via Spearphishing Link/Attachment, execution via Scheduled Task, stealth via DLL side-loading, and collection using AutoIt backdoor, BADNEWS, NDiskMonitor, QuasarRAT, and PowerSploit, with C2 using Standard Encoding. Defenders should focus on email filtering for phishing, monitoring for suspicious Scheduled Tasks and Registry Run Keys activity, and detecting C2 traffic associated with known RATs like QuasarRAT.
QUILTED TIGER
ChinastratsPatchworkMonsoon
nation-state
Dropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and economic targets using a custom set of attack tools. Its victims are all involved with China’s foreign relations in some way, and are generally caught through spear-phishing or watering hole attacks.
origin (suspected)
🇮🇳India· state-sponsoredattribution confidence: medium (50)