Patchwork APT, also known as Dropping Elephant, is a cyber-espionage group that some security vendors believe may be based in India. The group appears to have changed its modus operandi and has begun targeting private companies from various countries around the world.
The Patchwork APT's work came to light earlier this month, when security firm Cymmetria published a report on its activities.

The company nicknamed the group “the copy-paste APT,” due to their habit of putting together malware using low-quality code that is publicly available.
In a report published by Kaspersky a few days later, it was revealed that the group was primarily targeting government organizations in countries around Southeast Asia.
Symantec researchers claim to have found new evidence that the group has expanded to target private businesses.
This evidence suggests that the group had not updated its TTPs and continued to use spear-phishing emails.
In the vast majority of cases, these emails contain malicious PowerPoint files that attempt to exploit CVE-2014-4114 to install malware on the target’s computer.
The new campaign also used Word documents that exploit CVE-2015-1641 and CVE-2012-0158, and in some cases, spear-phishing emails did not come with an attachment, but contained links to a website where the user would download the malicious file themselves.
Symantec says that these files attempted to install the Enfourks and Steladok trojans, which could collect sensitive information from “infected” computers and upload it to online servers.
