Threat actor · all actors
PatchworkG0040 state
🇮🇳 IN
aka Patchwork, Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover, QUILTED TIGER, Sarit, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, VICEROY TIGER, Donot Team, APT-C-35, SectorE02, Orange Kala
Last updated: 2026-08-20
About this actor
VICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors. Older activity targeted multiple sectors and countries; however, since 2015 this adversary appears to focus on entities in Pakistan with a particular focus on government and security organizations. This adversary consistently leverages spear phishing emails containing malicious Microsoft Office documents, malware designed to target the Android mobile platform, and phishing activity designed to harvest user credentials. In March 2017, the 360 Chasing Team found a sample of targeted attacks that confirmed the previously unknown sample of APT's attack actions, which the organization can now trace back at least in April 2016. The chasing team named the attack organization APT-C-35. In June 2017, the 360 Threat Intelligence Center discovered the organization’s new attack activity, confirmed and exposed the gang’s targeted attacks against Pakistan, and analyzed in detail. The unique EHDevel malicious code framework used by the organization.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 63 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1005Data from Local System ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.001Binary Padding ↗T1027.002Software Packing ↗T1027.005Indicator Removal from Tools ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1055.012Process Hollowing ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1102Web Service ↗T1102.001Dead Drop Resolver ↗T1105Ingress Tool Transfer ↗T1112Modify Registry ↗T1119Automated Collection ↗T1132Data Encoding ↗T1132.001Standard Encoding ↗T1189Drive-by Compromise ↗T1197BITS Jobs ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1548Abuse Elevation Control Mechanism ↗T1548.002Bypass User Account Control ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1559Inter-Process Communication ↗T1559.002Dynamic Data Exchange ↗T1560Archive Collected Data ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1587Develop Capabilities ↗T1587.002Code Signing Certificates ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1598Phishing for Information ↗T1598.003Spearphishing Link ↗T1680Local Storage Discovery ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 43 / 63 | 68% |
CM-6 | 37 / 63 | 59% |
CM-2 | 35 / 63 | 56% |
SI-3 | 34 / 63 | 54% |
AC-6 | 25 / 63 | 40% |
CA-7 | 24 / 63 | 38% |
CM-7 | 23 / 63 | 37% |
SC-7 | 22 / 63 | 35% |
AC-3 | 21 / 63 | 33% |
SI-2 | 21 / 63 | 33% |
AC-4 | 20 / 63 | 32% |
AC-2 | 19 / 63 | 30% |
SI-7 | 19 / 63 | 30% |
CM-8 | 14 / 63 | 22% |
RA-5 | 14 / 63 | 22% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Sidewinder 0.42
- BRONZE BUTLER 0.41
- Cobalt Group 0.37
- APT37 0.36
- MuddyWater 0.35
Same nation-state
- C0011 1.00
- Tata Consultancy Services (Epic Systems case) 1.00
- Sidewinder 1.00
- BITTER 1.00
- Indian Cyber Force 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00