IndiaWidely attributedUnknownMITRE G0040

Patchwork

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
7.5
Moderate signal strength
Mentions13
Sources5
High conf.9
Last seenJun 2026
First observed
2017-05-31
Last active
Origin
India
Aliases
6
Techniques
41
Campaigns
0
India

Attribution signals

13 mentions · 5 sources
#1documentedhigh
InfrastructureHUMINT
recorded-future
May 2026

"Researchers at the US Naval War College and Tel Aviv University documented systematic Border Gateway Protocol (BGP) hijacking by China Telecom between 2016 and 2019, which redirected traffic from US, Canadian, and Scandinavian networks through Chinese infrastructure."

#2observedhigh
Infrastructure
mandiant
May 2026

"In a single seven day period in January 2026, GTIG observed over 550 individual threat groups that we track utilizing IP addresses tracked as IPIDEA exit nodes to obfuscate their activities, including groups from China, DPRK, Iran and Russia."

#3focusedhigh
VictimologyGeopoliticalTTP match
rapid7
May 2026

"Russian and Chinese campaigns focused heavily on intelligence collection, telecommunications infrastructure, and persistent access operations designed to remain undetected over long periods of time"

#4seenhigh
TTP match
ncsc-uk-all
May 2026

"we have seen a deliberate shift in cyber groups based in China utilising these networks to hide their malicious activity"

#5according tohigh
HUMINT
zack-whittaker
Jun 2026

"Spies working for Chinese intelligence are using job search and recruitment websites, including LinkedIn, to lure Western workers into sharing sensitive information, according to a joint advisory by the FBI, the U.K.'s security service MI5, and the governments of Australia, Canada, and New Zealand."

#6likelyhigh
Infrastructure
infosecurity-magazine
Jun 2026

"While previous incidents involving massive redirection of internet traffic through China show Beijing is likely up to something similar, Ferguson claimed."

#7likelyhigh
TTP match
xforce
Jun 2026

"It's likely to have been developed by Chinese nation-state actors."

#8likelyhigh
TTP match
xforce
Jun 2026

"It's likely to have been developed by Chinese nation-state actors based on the TTPs observed."

#9believed to bemoderate
TTP match
ncsc-uk-all
May 2026

"attacker tactics which are believed to be used by the majority of China-linked actors to obscure malicious cyber activity"

#10suggestinglow
TTP matchGeopolitical
bleepingcomputer
Jun 2026

"Analysis of this activity shows a clear focus on identifying vulnerable infrastructure shortly after public vulnerability disclosures, suggesting that reconnaissance output is rapidly operationalized by China-nexus advanced persistent threat (APT) actors"

#11unspecifiedunspecified
Infrastructure
ncsc-uk-all
May 2026

"China-nexus cyber actors have moved from using individually procured infrastructure to operating large scale "covert networks" – botnets built from compromised routers, and other edge devices."

#12unspecifiedhigh
HUMINTGeopolitical
zack-whittaker
Jun 2026

"China's military intelligence services "ultimately seek to acquire privileged military, political and economic intelligence that can provide China with a strategic and tactical advantage over the Five Eyes,""

Hedge terms observed

according tobelieved to bedocumentedfocusedlikelyobservedseensuggestingunspecified