IndiaWidely attributedUnknownMITRE G0040

Patchwork

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
10.9
High signal strength
Mentions21
Sources7
High conf.10
Last seenJun 2026
First observed
2017-05-31
Last active
Origin
India
Aliases
6
Techniques
41
Campaigns
0
India

Attribution signals

21 mentions · 7 sources
#1attackedhigh
VictimologyGeopolitical
dark-reading
Jun 2026

"China-linked espionage groups have attacked at least a dozen nations in the region"

#2state-sponsored cyber activityhigh
Unspecified
cisa
May 2026

"The authoring agencies are aware of recent People's Republic of China (PRC) state-sponsored cyber activity"

#3documentedhigh
InfrastructureHUMINT
recorded-future
May 2026

"Researchers at the US Naval War College and Tel Aviv University documented systematic Border Gateway Protocol (BGP) hijacking by China Telecom between 2016 and 2019, which redirected traffic from US, Canadian, and Scandinavian networks through Chinese infrastructure."

#4observedhigh
Infrastructure
mandiant
May 2026

"In a single seven day period in January 2026, GTIG observed over 550 individual threat groups that we track utilizing IP addresses tracked as IPIDEA exit nodes to obfuscate their activities, including groups from China, DPRK, Iran and Russia."

#5seenhigh
TTP match
ncsc-uk-all
May 2026

"we have seen a deliberate shift in cyber groups based in China utilising these networks to hide their malicious activity"

#6focusedhigh
VictimologyGeopoliticalTTP match
rapid7
May 2026

"Russian and Chinese campaigns focused heavily on intelligence collection, telecommunications infrastructure, and persistent access operations designed to remain undetected over long periods of time"

#7seems likelyhigh
GeopoliticalVictimology
dark-reading
Jun 2026

"it seems likely that the Czech Republic is among the recurrent intelligence-collection priorities of China-aligned APTs in Europe."

#8will likelyhigh
Geopolitical
recorded-future
Jun 2026

"Russian, Chinese, and Iranian state-sponsored threat groups will likely use the tournament as an intelligence collection opportunity, targeting executives, VIP attendees, national delegations, media partners, telecommunications providers, airlines, hotels, event logistics firms, and commercial affiliates."

#9most likelyhigh
Geopolitical
recorded-future
Jun 2026

"China is most likely to pursue targeted espionage, while Russia and Iran pose a higher risk of more disruptive attacks through proxy hacktivism."

#10likelyhigh
Geopolitical
recorded-future
May 2026

"Chinese economic espionage operations are likely targeting encrypted data with long-term intelligence value, including biometric identifiers, covert source identities, and weapons designs."

#11assessed with moderate confidence as being affiliated withmoderate
Unspecified
checkpoint
May 2026

"the activity was assessed with moderate confidence as being affiliated with a Chinese nexus"

Campaign: Operation TrueChaos
#12believed to bemoderate
TTP match
ncsc-uk-all
May 2026

"attacker tactics which are believed to be used by the majority of China-linked actors to obscure malicious cyber activity"

Hedge terms observed

assessed with moderate confidence as being affiliated withattackedbelieved to bedocumentedfocusedindicatelikelymoderate confidencemost likelyobservedseems likelyseenstate-sponsored cyber activityunspecifiedusuallywill likely