Rewterz Threat Alert – PatchWork APT Group Targeting Pakistan – Active IOCs
Severity
High
Analysis Summary
PatchWork, (also known as Mahabusa, White Elephant, hangOver, VICEROY TIGER, and The Dropping Elephant) is an APT that mainly conducts cyber-espionage activities against Asian countries especially against China and Pakistan. Threat actors are now targeting Federal Board of Revenue (FBR) in Pakistan in a series of spear phishing mails that looks like a document for Special relief package and dropping a backdoor when enabling the macros with a 17 year old MS Office Flaw (CVE-2017-11882) a memory corruption issue which can lead to remote code execution without user interaction if exploited correctly on a vulnerable machine. This vulnerability is generally used to deploy spyware to steal information from the victim’s machine for later gains and use against the victims.