Published on August 7, 2026

Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones


Severity

Medium

Detail

Patchwork also known as Dropping Elephant is an advanced espionage threat group that targets both Windows and Android devices through deceptive PDF shortcut files and trojanized chat applications. The campaign is designed to steal sensitive information, maintain persistent access, and conduct long-term surveillance against government, defense, energy, research, aviation, financial, and technology sectors.

How?

Patchwork delivers malware to Windows users through malicious LNK (shortcut) files disguised as PDF documents, often themed around government or energy-related topics. When opened, the shortcut silently launches a hidden PowerShell downloader, displays a legitimate decoy PDF to avoid suspicion, and installs additional malware in the background.

The malware establishes persistence by creating scheduled tasks such as GoogleErrorReport and NewErrorReport, while abusing legitimate executables (e.g., Fondue[.]exe and vlc[.]exe) for DLL side-loading. It then injects its remote access tool (RAT) into trusted Windows processes, allowing attackers to evade detection while collecting system information, executing commands, capturing screenshots, and exfiltrating sensitive data.

For Android devices, Patchwork relies on social engineering and romance-themed conversations to convince victims to install trojanized chat applications outside official app stores. One identified application, Wave Chat, masquerades as a legitimate messaging app while secretly monitoring user activity.

The Android malware can log keystrokes, steal contacts, messages, notifications, and stored files, record phone calls and ambient audio, capture images using the device camera, and maintain persistence after reboot. These capabilities enable attackers to conduct extensive surveillance and compromise both personal and organizational information.

Indicators of Compromise (IoCs)

The following IOCs are associated with this campaign and should be monitored to help identify potential infections:

TypeIndicatorDescription
Domainexpouav[.]orgDelivery domain used to host Patchwork payloads.
Domainroseserve[.]orgCommand-and-control domain used in a Türkiye-focused operation.
Domainchinagreenenergy[.]orgStaging domain associated with the China-themed shortcut chain.
Domainfich[.]buzzDirect-download infrastructure associated with trojanized Android applications.
URLhttps://chinagreenenergy[.]org/doc/35566/SXxlsURL used to retrieve the decoy PDF and campaign components.
File nameGRES3001[.]lnkMalicious shortcut disguised as a PDF document.

Conclusion

Patchwork continues to evolve its espionage operations by combining deceptive Windows shortcut files with trojanized Android chat applications to compromise both desktop and mobile environments. Organizations should educate users to avoid opening suspicious shortcut files, restrict PowerShell abuse, monitor scheduled tasks and unusual process activity, deploy endpoint detection and response (EDR) solutions, and enforce installation of mobile applications only from trusted app stores. Continuous monitoring for the IOCs can help detect and mitigate potential intrusions before significant data loss occurs.

Source

https://cybersecuritynews.com/fake-pdfs-chat-apps-let-patchwork-spy/