Alpha Cyber

Patchwork Unmasked: Mapping the Espionage Infrastructure Behind chinastrats.com

From Governments to Global Industry The Growing Reach of a Persistent Threat Group Cyber-espionage is no longer confined to state secrets.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Dropping Elephant APT PIC

chinastrats.com and Patchwork’s Expanding Target Spectrum

From Governments to Global Industry The Growing Reach of a Persistent Threat Group

Cyber-espionage is no longer confined to state secrets.
Recent infrastructure analysis has revealed that the Patchwork APT group operating under domains such as chinastrats.com has broadened its campaigns beyond traditional diplomatic and military targets. Today, defense contractors, media organizations, tech firms, academic institutions, and NGOs are increasingly within their crosshairs.

About Patchwork (aka Dropping Elephant)

Active since at least 2015, Patchwork is an Indian based cyber-espionage group known for leveraging social engineering, phishing emails, and malicious Microsoft Office documents embedded with VBA scripts and AutoIT-based droppers. These documents are often disguised as credible government or military files.

In their latest wave of attacks, the group has shifted from purely geopolitical targets to a broader selection of industry sectors a significant pivot that increases risk across the board.


Infrastructure Mapping: What We Discovered

Patchwork APT chinastrats.com Graph

Our research team mapped a network of phishing domains and delivery infrastructure used by Patchwork to conduct espionage operations. These domains are crafted to appear legitimate often mimicking defense or intelligence agencies to enhance credibility and trick users into downloading malicious files or visiting spoofed portals.

Domains such as:

chinastrats.com
milresearchcn.com
modgovcn.com
nudtcn.com
81-cn.net
socialfreakzz.com

demonstrate how Patchwork crafts its infrastructure to blend into trusted ecosystems, increasing the likelihood of successful compromise while evading basic detection systems.


Payload Analysis: Weaponized Documents

Patchwork’s delivery mechanism primarily uses .pps (PowerPoint Slide Show) files with embedded malware. These files often carry compelling geopolitical titles to appear legitimate to high-value targets.

Example malicious filenames include:

PLA_UAV_DEPLOYMENT.pps
MilitaryReforms2.pps
maritime_dispute.pps

Once executed, these files deploy AutoIT-based droppers that install backdoors, exfiltrate data, and allow remote command execution.

Indicators of Compromise (IOCs)

Below is a curated table of domains and malicious files identified during our infrastructure analysis. These IOCs should be blocked or monitored immediately to reduce exposure to Patchwork-linked threats.


Malicious Domains (C2 and Staging Infrastructure)

TypeIndicator
Domainchinastrats.com
Domainepg-cn.com
Domainextremebolt.com
Domaininfo81.com
Domainlujunxinxi.com
Domainmilitaryworkerscn.com
Domainmilresearchcn.com
Domainmodgovcn.com
Domainnewsnstat.com
Domainnudtcn.com
Domainsocialfreakzz.com
Domain81-cn.net
Domaincnmilit.com

Malicious Files (Trojan.PPDropper)

Detection NameMD5 HashFile Name
Trojan.PPDropper0bbff4654d0c4551c58376e6a99dfda0(Filename not captured)
Trojan.PPDropper1de10c5bc704d3eaf4f0cfa5ddd63f2dMilitaryReforms2.pps
Trojan.PPDropper2ba26a9cc1af4479e99dcc6a0e7d5d672016_China_Military_PowerReport.pps
Trojan.PPDropper375f240df2718fc3e0137e109eef57eePLA_UAV_DEPLOYMENT.pps
Trojan.PPDropper38e71afcdd6236ac3ad24bda393a81c6militarizationofsouthchinasea_1.pps
Trojan.PPDropper3e9d1526addf2ca6b09e2fdb5fd4978fHow_to_easily_clean_an_infected_computer.pps
Trojan.PPDropper475c29ed9373e2c04b7c3df6766761ebPLA_Forthcoming_Revolution_in_Doctrinal_Affairs.pps
Trojan.PPDropper4dbb8ad1776af25a5832e92b12d4bfffmaritime_dispute.pps

Risk to Your Organization

Patchwork is not just another threat actor. If your organization:

Operates in government, defense, policy, or research
Relies heavily on Microsoft Office tools
Manages or accesses strategic geopolitical information

then you’re squarely within the scope of Patchwork’s expanding campaign.

Their use of trusted-looking files and believable infrastructure makes these attacks difficult to detect without active monitoring and proactive defense strategies.

How We Can Help

At Alpha Cyber, we specialize in:

  • Infrastructure Mapping & Attribution
  • IOC Monitoring & Enforcement
  • Advanced Threat Hunting
  • Malware Reverse Engineering
  • Real-Time Threat Intelligence Feeds

By focusing on attacker infrastructure, we help you defend against not just one campaign, but entire families of threats.

Don’t Wait for the Next Exploit

If your security program isn’t actively tracking APT infrastructure, you’re at risk of silent compromise.

Let us assess your exposure to Patchwork and other high-risk actors.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]