Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones

August 7, 2026

Patchwork, also known as Dropping Elephant, is using fake documents and chat applications to spy on computer and phone users.

The long-running espionage group has built separate attack paths for Windows systems and Android devices, allowing it to collect sensitive information from both environments.

On Windows, the operation starts with a shortcut file disguised as a PDF document. Opening it launches a hidden PowerShell downloader, displays a decoy file, and quietly installs malware in the background.

The technique resembles other malicious shortcut file campaigns that use familiar documents to trick targets into starting an infection.

Analysts at Picus Security identified the campaign activity and noted that Patchwork has targeted government, defense, energy, research, aviation, financial, and technology organizations.

The group has been active since at least 2015 and has conducted operations across Asia, Europe, Türkiye, and the United States.

Picus Security said in a report shared with Cyber Security News (CSN) that the group combines phishing, social engineering, hidden scripts, and mobile surveillance tools.

Its latest activity shows how one threat actor can move from a deceptive desktop file to a compromised smartphone, placing personal and organizational data at risk.

Fake PDFs and Chat Apps

The Windows infection chain uses a malicious shortcut named GRES3001.lnk, which is made to look like a PDF connected to a China-themed energy contract.

Once opened, the file starts PowerShell through conhost.exe, downloads a harmless-looking PDF for the victim, and retrieves additional components without drawing attention.

The malware creates scheduled tasks named GoogleErrorReport and NewErrorReport to run repeatedly. It also abuses legitimate-looking files, including Fondue.exe and vlc.exe, to load malicious code.

This persistence method closely matches the GoogleErrorReport persistence technique reported in earlier Patchwork activity.

Patchwork hides its final remote access tool inside trusted Windows processes. It decrypts payloads from local files, loads them into memory, and can disable or weaken security checks within the infected process.

The malware can collect system details, list files, run commands, capture screenshots, and send selected data back to its operators.

The campaign underlines why a document icon should not be treated as proof that a file is safe. Users should be cautious with unexpected attachments, especially files that show a PDF icon but carry an LNK extension.

Security teams should also review scheduled tasks, monitor unusual PowerShell activity, and investigate programs running from public or temporary folders.

Chat Lures Turn Phones Into Listening Devices

Patchwork uses romance-themed conversations to persuade targets to leave regular messaging services and install trojanized Android chat applications.

These apps are distributed outside official app stores and appear to offer ordinary messaging features while activating surveillance functions in the background.

Similar risks have appeared in trojanized messaging app threats, where fake communication tools collect data after installation.

One identified app, Wave Chat, can read visible chat content, log keystrokes, collect notifications, steal contacts and messages, and search device storage for documents, images, and audio.

It can also record surrounding sound, phone calls, and calls made through other communication apps, then upload the captured material to attacker-controlled infrastructure.

The Android implant can restart after the phone reboots, helping it continue collecting data without further interaction. It may also capture images with the phone camera, gather call records, and delete selected files, contacts, or call-history entries.

These capabilities make the threat particularly serious for people handling sensitive work or private communications.

Organizations should test whether their security controls can detect suspicious PowerShell execution, malicious shortcut files, unusual scheduled tasks, and unauthorized Android applications.

Users should install apps only from trusted stores, review permission requests carefully, and avoid moving conversations to unfamiliar chat apps after being contacted by strangers.

Awareness of PowerShell-based malware delivery can also help teams recognize the early signs of a Windows compromise.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain expouav[.]org Delivery domain used to host Patchwork payloads. 
Domain roseserve[.]org Command-and-control domain used in a Türkiye-focused operation. 
URL https://chinagreenenergy[.]org/doc/35566/SXxls URL used to retrieve the decoy PDF and campaign components. 
Domain chinagreenenergy[.]org Staging domain associated with the China-themed shortcut chain. 
Domain fich[.]buzz Direct-download infrastructure associated with trojanized Android applications. 
Android package com.yoho.talk Attacker-controlled Android application package. 
Domain gcl-power[.]org Windows RAT command-and-control domain. 
URI path /prjozifvkpkfhkr/gedhagammgjvvva/ RAT command-polling path on the command-and-control server. 
URI path /prjozifvkpkfhkr/spxbjdhxtapivrk/ RAT screenshot upload path. 
File name GRES3001.lnk Malicious shortcut disguised as a PDF document. 
File name APPWIZ.cpl Malicious loader used for DLL side-loading. 
File name libvlc.dll Malicious side-loading library. 
File name vlc.log Encrypted payload file used by the loader. 
File name editor.dat Encrypted payload file decrypted by APPWIZ.cpl. 

tionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Original article can be found here