Dropping Elephant

Threat Actor updated 5 months ago (2024-05-05T03:18:29.866Z)
Download STIX
Preview STIX
Dropping Elephant, also known as Patchwork or Monsoon, is a threat actor primarily targeting high-profile diplomatic and economic entities. This Indian Advanced Persistent Threat (APT) group was identified by Volexity in March and April 2018 conducting multiple spear phishing campaigns. The group's modus operandi includes the use of Chinese-themed content as bait to compromise target networks, as observed by Symantec Security Response. Dropping Elephant's activities have been closely monitored by cybersecurity firms such as Kaspersky Lab, which has detected artifacts related to this threat actor. The group employs two main infection vectors that revolve around an elaborately maintained social engineering theme – foreign relations with China. In the case of Dropping Elephant, the backdoor downloads encoded blobs that are then decoded to PowerShell command-line scripts. This unique approach has allowed the group to maintain its operations effectively. Recent analysis from Cymmetria provides further data about these attacks, highlighting the sophisticated nature of Dropping Elephant's strategies. Despite the significant threat it poses, the VB2023 paper titled "The Dropping Elephant never dropped" suggests an ongoing resilience of this APT group. Furthermore, recent observations from Unit 42 indicate continued campaigns against targets located in the Indian subcontinent. These findings underscore the importance of maintaining vigilance and robust cybersecurity measures to counter threats posed by groups like Dropping Elephant.
Description last updated: 2024-05-05T02:47:01.960Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Dropping Elephant Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more