VYPR
researchPublished Aug 7, 2026· 1 source

Patchwork Espionage Group Targets Windows and Android with Deceptive PDFs and Trojanized Chat Apps

The persistent Patchwork (Dropping Elephant) threat actor is employing sophisticated social engineering tactics, using fake PDF documents and trojanized chat applications to compromise both Windows PCs and Android devices.

The long-standing espionage group known as Patchwork, also referred to as Dropping Elephant, has been observed deploying a dual-pronged attack strategy targeting both Windows and Android users. This campaign leverages deceptive social engineering techniques, including fake PDF documents and compromised chat applications, to infiltrate systems and exfiltrate sensitive data.

For Windows targets, the initial infection vector involves malicious LNK (shortcut) files disguised as PDF documents. When a user opens one of these files, it silently triggers a PowerShell downloader. This downloader then displays a decoy PDF to the victim, creating a plausible cover while it proceeds to install malware in the background. This method is a common tactic, relying on the familiarity of document icons to trick users into executing malicious code.

Analysts at Picus Security have identified Patchwork's extensive targeting history, which includes government, defense, energy, research, aviation, financial, and technology organizations across Asia, Europe, Türkiye, and the United States. The group has been active since at least 2015, demonstrating a consistent and broad operational scope. Their latest campaign highlights the adaptability of threat actors, moving seamlessly from desktop-based attacks to mobile surveillance.

The Windows infection chain specifically utilizes a malicious shortcut file, GRES3001.lnk, crafted to appear as a PDF related to a China-themed energy contract. Upon execution, PowerShell is launched via conhost.exe. The malware establishes persistence by creating scheduled tasks named GoogleErrorReport and NewErrorReport, mirroring previously observed Patchwork techniques. It also abuses legitimate executable files like Fondue.exe and vlc.exe to load malicious code, further evading detection.

Patchwork's Windows malware is designed to hide its final remote access tool within trusted system processes. It decrypts payloads in memory, capable of disabling security features. The implant can gather system information, list files, execute commands, capture screenshots, and exfiltrate selected data to its command-and-control (C2) infrastructure, which includes domains like expouav[.]org and gcl-power[.]org.

On the Android front, Patchwork employs romance-themed lures to entice victims into abandoning mainstream messaging applications for trojanized chat apps distributed outside official app stores. One such application, Wave Chat, masquerades as a legitimate messaging service but contains hidden surveillance capabilities. These include reading chat content, logging keystrokes, stealing contacts and messages, and searching device storage for sensitive files.

Beyond data theft, the Android implant can record surrounding audio, phone calls, and calls made through other communication apps. It can also capture images via the device camera and access call logs. The malware is designed to maintain persistence, restarting after device reboots and capable of deleting selected data to cover its tracks. This comprehensive surveillance suite poses a significant risk to individuals handling sensitive work or private communications.

Security recommendations for organizations include monitoring for suspicious PowerShell activity, malicious shortcut files, and unauthorized Android applications. Users are advised to exercise extreme caution with unexpected attachments, verify file extensions, and only install applications from trusted sources. Awareness of common infection chains and persistence mechanisms is crucial for both end-users and security professionals to mitigate the evolving threats posed by groups like Patchwork.

Synthesized by Vypr AI