cognitive cybersecurity intelligence

News and Analysis

Search

Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones

Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones

Patchwork, also known as Dropping Elephant, is using fake documents and chat applications to spy on computer and phone users.

The long-running espionage group has built separate attack paths for Windows systems and Android devices, allowing it to collect sensitive information from both environments.

On Windows, the operation starts with a shortcut file disguised as a PDF document. Opening it launches a hidden PowerShell downloader, displays a decoy file, and quietly installs malware in the background.

The technique resembles other malicious shortcut file campaigns that use familiar documents to trick targets into starting an infection.

Analysts at Picus Security identified the campaign activity and noted that Patchwork has targeted government, defense, energy, research, aviation, financial, and technology organizations.

The group has been active since at least 2015 and has conducted operations across Asia, Europe, Türkiye, and the United States.

Picus Security said in a report shared with Cyber Security News (CSN) that the group combines phishing, social engineering, hidden scripts, and mobile surveillance tools.

Its latest activity shows how one threat actor can move from a deceptive desktop file to a compromised smartphone, placing personal and organizational data at risk.

Fake PDFs and Chat Apps

The Windows infection chain uses a malicious shortcut named GRES3001.lnk, which is made to look like a PDF connected to a China-themed energy contract.

Once opened, the file starts PowerShell through conhost.exe, downloads a harmless-looking PDF for the victim, and retrieves additional components without drawing attention.

The malware creates scheduled tasks named GoogleErrorReport and NewErrorReport to run repeatedly. It also abuses legitimate-looking files, including Fondue.exe and vlc.exe, to load malicious code.

This persistence method closely matches the GoogleErrorReport persistence technique reported in earlier Patchwork activity.

Patchwork hides its final remote access tool inside trusted Windows processes. It decrypts payloads from local files, loads them into memory, and can disable or weaken security checks within the infected process.

The malware can collect system details, list files, run commands, capture screenshots, and send selected data back to its operators.

The campaign underlines why a document icon should not be treated as proof that a file is safe. Users should be cautious with unexpected attachments, especially files that show a PDF icon but carry an LNK extension.

Security teams should also review scheduled tasks, monitor unusual PowerShell activity, and investigate programs running from public or temporary folders.

Chat Lures Turn Phones Into Listening Devices

Patchwork uses romance-themed conversations to persuade targets to leave regular messaging services and install trojanized Android chat applications.

These apps are distributed outside official app stores and appear to offer ordinary messaging features while activating surveillance functions in the background.

Similar risks have appeared in trojanized messaging app threats, where fake communication tools collect data after installation.

One identified app, Wave Chat, can read visible chat content, log keystrokes, collect notifications, steal contacts and messages, and search device storage for documents, images, and audio.

It can also record surrounding sound, phone calls, and calls made through other communication apps, then upload the captured material to attacker-controlled infrastructure.

The Android implant can restart after the phone reboots, helping it continue collecting data without further interaction. It may also capture images with the phone camera, gather call records, and delete selected files, contacts, or call-history entries.

These capabilities make the threat particularly serious for people handling sensitive work or private communications.

Organizations should test whether their security controls can detect suspicious PowerShell execution, malicious shortcut files, unusual scheduled tasks, and unauthorized Android applications.

Users should install apps only from trusted stores, review permission requests carefully, and avoid moving conversations to unfamiliar chat apps after being contacted by strangers.

Awareness of PowerShell-based malware delivery can also help teams recognize the early signs of a Windows compromise.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionDomainexpouav[.]orgDelivery domain used to host Patchwork payloads. Domainroseserve[.]orgCommand-and-control domain used in a Türkiye-focused operation. URLhttps://chinagreenenergy[.]org/doc/35566/SXxlsURL used to retrieve the decoy PDF and campaign components. Domainchinagreenenergy[.]orgStaging domain associated with the China-themed shortcut chain. Domainfich[.]buzzDirect-download infrastructure associated with trojanized Android applications. Android packagecom.yoho.talkAttacker-controlled Android application package. Domaingcl-power[.]orgWindows RAT command-and-control domain. URI path/prjozifvkpkfhkr/gedhagammgjvvva/RAT command-polling path on the command-and-control server. URI path/prjozifvkpkfhkr/spxbjdhxtapivrk/RAT screenshot upload path. File nameGRES3001.lnkMalicious shortcut disguised as a PDF document. File nameAPPWIZ.cplMalicious loader used for DLL side-loading. File namelibvlc.dllMalicious side-loading library. File namevlc.logEncrypted payload file used by the loader. File nameeditor.datEncrypted payload file decrypted by APPWIZ.cpl. 

tionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

The post Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

Growing Up The Hard Way

Growing Up The Hard Way

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and