Patchwork, also known as Dropping Elephant, employs fake documents and chat apps to spy on computer and phone users This article explores chat apps spy. . This long-running espionage group has developed distinct attack paths tailored for Windows systems and Android devices, enabling it to gather sensitive information from both environments.

Security analysts at Picus Security pinpointed the campaign's activities and noted that Patchwork has targeted organizations in various sectors including government, defense, energy, research, aviation, financial, and technology. A report from Picus Security shared with ZeroOwl (ZeroOwl) reveals that the group combines phishing, social engineering, hidden scripts, and mobile surveillance tools. Upon activation, the file initiates PowerShell via conhost.exe, downloading a seemingly benign PDF for the victim and retrieving additional components without arousing suspicion.

Malware collects system details, lists files, runs commands, captures screenshots, and sends selected data back to its operators. ChatLures Persuades Phones into Listening Devices Patchwork employs romance-themed conversations to convince targets to switch from regular messaging services to trojanized Android chat applications. One identified app, WaveChat, can read visible chat content, log keystrokes, capture notifications, steal contacts and messages, search device storage for documents, images, and audio, and record surrounding sound, phone calls, and other apps' communications.

Users should only install apps from trusted stores, carefully review permission requests, and avoid moving conversations to unfamiliar chat apps after being contacted by strangers.