APT
ATLAS
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
LOADING
Patchwork (aka Patchwork, VICEROY TIGER) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
Patchwork
G0040
APT
IN · India
AKA
VICEROY TIGER · Operation Hangover · Dropping Elephant · Monsoon · Chinastrats · SectorE02 · ATK11 · Hangover
CrowdStrike
:
QUILTED TIGER
Microsoft
:
Vibrant Opal
Mandiant
:
APT-C-09
MITRE
:
G0040
Secureworks
:
IRON PANDA
Targets
21
Sectors
14
Threat types
1
GIRs covered
0/480
Active since
2009
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 8 other aliases
Open Rosetta Stone
CrowdStrike
QUILTED TIGER
Mandiant
APT-C-09
Microsoft
Vibrant Opal
MITRE
G0040
Secureworks
IRON PANDA
UNATTRIBUTED ALIASES
VICEROY TIGER
Operation Hangover
Dropping Elephant
Monsoon
Chinastrats
SectorE02
ATK11
Hangover
Victimology
Geographic footprint · 21 countries
Region filter
Export
origin · India
targeted countries · 21
ASIA ·
15
United Arab Emirates
·
Afghanistan
·
Bangladesh
·
China
·
Hong Kong
·
India
·
Iran
·
Sri Lanka
·
Mongolia
·
Oman
·
Pakistan
·
Saudi Arabia
·
Singapore
·
Türkiye
·
Taiwan
OCEANIA ·
1
Australia
AMERICAS ·
2
Canada
·
United States
EUROPE ·
3
United Kingdom
·
Norway
·
Russia
Sectors targeted
14 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Aviation
22 actors
Financial Services
74 actors
Healthcare
47 actors
Technology
60 actors
Telecom
72 actors
NGOs & Dissidents
56 actors
Media & Journalism
49 actors
Private Sector (generic)
29 actors
Extractive Industries
8 actors
Dissidents (as targets)
16 actors
Maritime
24 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 27 techniques
Initial Access
· 3
T1189
Drive-by Compromise
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
Execution
· 6
T1053.005
Scheduled Task
Persistence
· 1
Credential Access
· 1
T1555.003
Credentials from Web Browsers
Discovery
· 3
T1033
System Owner/User Discovery
Lateral Movement
· 1
T1021.001
Remote Desktop Protocol
Collection
· 3
T1005
Data from Local System
T1119
Automated Collection
T1560
Archive Collected Data
Command And Control
· 2
T1102.001
Dead Drop Resolver
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 6
T1027.002
Software Packing
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
27 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT2
nation-state
China · 6 targets · since 2010
APT24
nation-state
China · 3 targets · since 2008
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.005
Visual Basic
T1203
Exploitation for Client Execution
T1204.001
Malicious Link
T1547.001
Registry Run Keys / Startup Folder
T1083
File and Directory Discovery
T1680
Local Storage Discovery
T1105
Ingress Tool Transfer
T1027.010
Command Obfuscation
T1036.005
Match Legitimate Resource Name or Location
T1055.012
Process Hollowing
T1070.004
File Deletion
T1197
BITS Jobs