Alpha Cyber

Dropping Elephant India-Linked Hackers Target Missile Firm in Sophisticated Cyber Espionage

2025 has seen a dramatic escalation in nation-state cyber threats, with “Dropping Elephant” an India-linked APT group (also known as Patchwork) spearheading a highly targeted campaign against Türkiye’s defense sector.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Dropping Elephant APT

Inside Operation Dropping Elephant: India-Linked Hackers Target Turkish Missile Firm in Sophisticated Cyber Espionage

2025 has seen a dramatic escalation in nation-state cyber threats, with “Dropping Elephant” an India-linked APT group (also known as Patchwork) spearheading a highly targeted campaign against Türkiye’s defense sector. Their latest operation, aimed at a leading Turkish precision-guided missile manufacturer, exploited a mix of advanced tactics and social engineering to breach vital R&D infrastructure.

How Did the Attack Happen?


The breach began with convincing spear-phishing emails disguised as invites to an international unmanned vehicle systems conference. These lures contained weaponized shortcut (LNK) files, harboring a five-stage payload chain that leveraged legitimate applications such as VLC Media Player and Microsoft Task Scheduler (a technique known as DLL side-loading) for stealthy malware delivery and persistence in the network.

The attackers used well-known living-off-the-land binaries and staged downloads to reduce detection and increase operational security. They mimicked trusted organizations including Türkiye’s own Pardus Linux distribution using typosquat domains like rosereserve.org and roseserve.org, and hosted command-and-control (C2) infrastructure on servers deliberately obfuscated behind international VPS providers. All these measures indicate patient, methodical operational planning.

Why Is This Attack Significant?


Technical Evolution: The group has refined its malware, moving from x64 DLLs to lighter x86 payloads with more complex command structures and less reliance on external libraries.
Geopolitical Motivation: The targeting aligns with heightened regional cooperation between Türkiye and Pakistan, and concurrent military tensions involving India.
Sector Focus: While once mainly active in Asia, the group now routinely targets defense, energy, financial, and governmental organizations worldwide.

Infrastructure Map and IOCs: What to Block Now

Below are the critical Indicators of Compromise (IOCs) from this attack. Block or monitor these in your organization’s security tools immediately:

TypeIndicatorActionNotes
IP Address193.140.63.90Block / MonitorPotential malicious IP
IP Address2.56.127.187Block / MonitorPotential malicious IP
Domainrosereserve.orgBlock / SinkholePhishing/C2 domain
Domainroseserve.orgBlock / SinkholeTyposquat of above domain
File Hash (MD5)01b12fc6509c7b431e3ee7142dbdb1bdBlock / Flag in AVMalware sample hash (MD5)
File Hash (MD5)01600b4f79b096111a096435b82378acBlock / Flag in AVMalware sample hash (MD5)
File Hash (SHA-256)8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2Block / Flag in AVMalware sample hash (SHA-256)

What Can You Do?


Patch and Educate: Social engineering is at the core of these attacks. Make sure your staff is trained to spot phishing attempts, and always keep your software up-to-date to avoid exploitation through old vulnerabilities.
Strengthen Defenses: Deploy threat intelligence feeds, respond quickly to alerts, and use endpoint detection and response (EDR) solutions to stop lateral movement and data theft.
Review Supply Chain Risks: Even non-technical partners can be vectors for highly targeted campaigns.

Let us help Click here for a free assessment

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]