Patchwork, also known as Dropping Elephant, is an espionage-focused advanced persistent threat (APT) that began operating since December 2015 This article explores malicious lnk shortcut. . This group targets government, defense, energy, aviation, research, finance, technology, pharmaceutical, NGO, and think tank organizations across Asia, Europe, Turkey, and the United States.
Their most recent activity highlights a continued focus on targeted phishing, deceptive document lures, stealthy Windows malware, and trojanized Android apps. The attackers use fake PDF shortcuts to deliver memory-resident remote access trojans (RATs), while mobile implants can steal messages, files, call records, keystrokes, audio, and images. Starting from a malicious .lnk shortcut disguised as a PDF document, one sample named GRES3001.lnk lured targets into the trap by presenting itself as a legitimate contract-completion PDF.
When clicked, PowerShell was launched via conhost.exe, allowing the script to download and open a decoy PDF while secretly retrieving additional malware components. The Remote Access Tool (RAT) can also exploit AMSI, Windows Lockdown Policy, and Event Tracing for Windows functionalities to weaken local scanning and telemetry. Once activated, the RAT gathers detailed information about the computer's name, username, operating system details, public IP address, country, running processes, and network settings.
Utilize in-browser data inspection from ANY.RUN to detect, investigate, and respond more quickly, enhancing your security operations center (SOC) and reducing Mean Time To Resolution (MTTR).












