Patchwork Unmasked: Mapping the Espionage Infrastructure Behind chinastrats.com
From Governments to Global Industry The Growing Reach of a Persistent Threat Group Cyber-espionage is no longer confined to state secrets.

chinastrats.com and Patchwork’s Expanding Target Spectrum
From Governments to Global Industry The Growing Reach of a Persistent Threat Group
Cyber-espionage is no longer confined to state secrets.
Recent infrastructure analysis has revealed that the Patchwork APT group operating under domains such as chinastrats.com has broadened its campaigns beyond traditional diplomatic and military targets. Today, defense contractors, media organizations, tech firms, academic institutions, and NGOs are increasingly within their crosshairs.
About Patchwork (aka Dropping Elephant)
Active since at least 2015, Patchwork is an Indian based cyber-espionage group known for leveraging social engineering, phishing emails, and malicious Microsoft Office documents embedded with VBA scripts and AutoIT-based droppers. These documents are often disguised as credible government or military files.
In their latest wave of attacks, the group has shifted from purely geopolitical targets to a broader selection of industry sectors a significant pivot that increases risk across the board.
Infrastructure Mapping: What We Discovered

Our research team mapped a network of phishing domains and delivery infrastructure used by Patchwork to conduct espionage operations. These domains are crafted to appear legitimate often mimicking defense or intelligence agencies to enhance credibility and trick users into downloading malicious files or visiting spoofed portals.
Domains such as:
chinastrats.commilresearchcn.commodgovcn.comnudtcn.com81-cn.netsocialfreakzz.com
demonstrate how Patchwork crafts its infrastructure to blend into trusted ecosystems, increasing the likelihood of successful compromise while evading basic detection systems.
Payload Analysis: Weaponized Documents
Patchwork’s delivery mechanism primarily uses .pps (PowerPoint Slide Show) files with embedded malware. These files often carry compelling geopolitical titles to appear legitimate to high-value targets.
Example malicious filenames include:
PLA_UAV_DEPLOYMENT.ppsMilitaryReforms2.ppsmaritime_dispute.pps
Once executed, these files deploy AutoIT-based droppers that install backdoors, exfiltrate data, and allow remote command execution.
Indicators of Compromise (IOCs)
Below is a curated table of domains and malicious files identified during our infrastructure analysis. These IOCs should be blocked or monitored immediately to reduce exposure to Patchwork-linked threats.
Malicious Domains (C2 and Staging Infrastructure)
| Type | Indicator |
|---|---|
| Domain | chinastrats.com |
| Domain | epg-cn.com |
| Domain | extremebolt.com |
| Domain | info81.com |
| Domain | lujunxinxi.com |
| Domain | militaryworkerscn.com |
| Domain | milresearchcn.com |
| Domain | modgovcn.com |
| Domain | newsnstat.com |
| Domain | nudtcn.com |
| Domain | socialfreakzz.com |
| Domain | 81-cn.net |
| Domain | cnmilit.com |
Malicious Files (Trojan.PPDropper)
| Detection Name | MD5 Hash | File Name |
|---|---|---|
| Trojan.PPDropper | 0bbff4654d0c4551c58376e6a99dfda0 | (Filename not captured) |
| Trojan.PPDropper | 1de10c5bc704d3eaf4f0cfa5ddd63f2d | MilitaryReforms2.pps |
| Trojan.PPDropper | 2ba26a9cc1af4479e99dcc6a0e7d5d67 | 2016_China_Military_PowerReport.pps |
| Trojan.PPDropper | 375f240df2718fc3e0137e109eef57ee | PLA_UAV_DEPLOYMENT.pps |
| Trojan.PPDropper | 38e71afcdd6236ac3ad24bda393a81c6 | militarizationofsouthchinasea_1.pps |
| Trojan.PPDropper | 3e9d1526addf2ca6b09e2fdb5fd4978f | How_to_easily_clean_an_infected_computer.pps |
| Trojan.PPDropper | 475c29ed9373e2c04b7c3df6766761eb | PLA_Forthcoming_Revolution_in_Doctrinal_Affairs.pps |
| Trojan.PPDropper | 4dbb8ad1776af25a5832e92b12d4bfff | maritime_dispute.pps |
Risk to Your Organization
Patchwork is not just another threat actor. If your organization:
Operates in government, defense, policy, or research
Relies heavily on Microsoft Office tools
Manages or accesses strategic geopolitical information
then you’re squarely within the scope of Patchwork’s expanding campaign.
Their use of trusted-looking files and believable infrastructure makes these attacks difficult to detect without active monitoring and proactive defense strategies.
How We Can Help
At Alpha Cyber, we specialize in:
- Infrastructure Mapping & Attribution
- IOC Monitoring & Enforcement
- Advanced Threat Hunting
- Malware Reverse Engineering
- Real-Time Threat Intelligence Feeds
By focusing on attacker infrastructure, we help you defend against not just one campaign, but entire families of threats.
Don’t Wait for the Next Exploit
If your security program isn’t actively tracking APT infrastructure, you’re at risk of silent compromise.
Let us assess your exposure to Patchwork and other high-risk actors.



