Dropping Elephant (Patchwork) Espionage APT Tactics and Tool... - #2689
Open
carlospolop wants to merge 1 commit into
Open
Dropping Elephant (Patchwork) Espionage APT Tactics and Tool...#2689carlospolop wants to merge 1 commit into
carlospolop wants to merge 1 commit into
Conversation
Collaborator
Author
🔗 Additional ContextOriginal Blog Post: https://picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools Content Categories: Based on the analysis, this content was categorized under "Windows Hardening → Windows Local Privilege Escalation → DLL Hijacking / Antivirus Bypass, with cross-references to Android Applications Pentesting → Accessibility Services Abuse and Reversing → Common API used in Malware". Repository Maintenance:
Review Notes:
Bot Version: HackTricks News Bot v1.0 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 Automated Content Update
This PR was automatically generated by the HackTricks News Bot based on a technical blog post.
📝 Source Information
🎯 Content Summary
Overview and impact
Dropping Elephant, also known as Patchwork, is an espionage-focused APT first observed in December 2015. It targets government, defense, energy, research, aviation, financial, technology, pharmaceutical, NGO, and think-tank organizations across Asia, Europe, Türkiye, and the United States. The post does not describe exploitation of a CVE; compromise instead depends on tailored phishing, social engineering, malicious LNK files, sideloaded Android applications, Power...
🔧 Technical Details
Shortcut masquerading and split-token PowerShell: A Windows shortcut can use a document-like icon and filename while launching PowerShell through another process such as
conhost.exe. Empty quotes can be inserted into PowerShell aliases and command names—such asiw''r,r''e''n, andg''cm sch*—because PowerShell reconstructs them during parsing. This preserves functionality while evading detections based on contiguous command strings. A stager can suppress progress output, retrieve a decoy and payloads, rename and copy components, create persistence, open the lure, and delete the original shortcut.Scheduled-task DLL or CPL side-loading: Place a trusted executable and an attacker-controlled library with the expected filename or export in the same writable directory, then create a recurring scheduled task that launches the trusted executable. Windows library-search behavior causes the trusted ho...
🤖 Agent Actions
ERROR: Codex exec failed (exit=1).
2026-08-11T19:02:48.072036Z ERROR codex_core::session: Failed to create session: required MCP servers failed to initialize: chack_tools: handshaking with MCP server failed: connection closed: initialize response
Error: thread/start: thread/start failed: error creating thread: Fatal error: Failed to initialize session: required MCP servers failed to initialize: chack_tools: handshaking with MCP server failed: connection closed: initialize response (code -32603)
This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.
📚 Repository Maintenance
All .md files have been checked for proper formatting (headers, includes, etc.).