Cyber Resilience

Threat actor · all actors

PatchworkG0040 state

🇮🇳 IN

aka Patchwork, Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover, QUILTED TIGER, Sarit, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, VICEROY TIGER, Donot Team, APT-C-35, SectorE02, Orange Kala

Last updated: 2026-08-20

0attributed CVEs
63ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

VICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors. Older activity targeted multiple sectors and countries; however, since 2015 this adversary appears to focus on entities in Pakistan with a particular focus on government and security organizations. This adversary consistently leverages spear phishing emails containing malicious Microsoft Office documents, malware designed to target the Android mobile platform, and phishing activity designed to harvest user credentials. In March 2017, the 360 Chasing Team found a sample of targeted attacks that confirmed the previously unknown sample of APT's attack actions, which the organization can now trace back at least in April 2016. The chasing team named the attack organization APT-C-35. In June 2017, the 360 Threat Intelligence Center discovered the organization’s new attack activity, confirmed and exposed the gang’s targeted attacks against Pakistan, and analyzed in detail. The unique EHDevel malicious code framework used by the organization.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0040

Microsoftweather-system names

MONSOON

CrowdStrikenation-animal names

QUILTED TIGERVICEROY TIGER

Palo Alto Unit 42constellation names

Thirsty Gemini

Unclassifiedno scheme matched

PatchworkHangover GroupDropping ElephantChinastratsOperation HangoverSaritAPT-C-09ZINC EMERSONATK11Orange AthosDonot TeamAPT-C-35SectorE02Orange Kala

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 63 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-443 / 6368%
CM-637 / 6359%
CM-235 / 6356%
SI-334 / 6354%
AC-625 / 6340%
CA-724 / 6338%
CM-723 / 6337%
SC-722 / 6335%
AC-321 / 6333%
SI-221 / 6333%
AC-420 / 6332%
AC-219 / 6330%
SI-719 / 6330%
CM-814 / 6322%
RA-514 / 6322%

Co-occurring actors

None.

Similar actors

Similar TTPs