Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Patchwork APT: Leveraging PowerShell to Create Scheduled Tasks and Deploy Final Payload

Patchwork, an advanced persistent threat (APT) group, also known as Dropping Elephant, Monsoon, and Hangover Group, has been observed utilizing a new PowerShell-based loader. This loader exploits Windows Scheduled Tasks to execute its final payload.

Patchwork, an advanced persistent threat (APT) group, also known as Dropping Elephant, Monsoon, and Hangover Group, has been observed utilizing a new PowerShell-based loader. This loader exploits Windows Scheduled Tasks to execute its final payload.

Active since 2015, Patchwork targets political and military intelligence in South and Southeast Asia. The group is known for its persistence and repurposing of existing tools rather than creating new exploits.

In the latest campaign, targets receive a Microsoft Office document containing a malicious macro. When enabled, this macro downloads an LNK shortcut file that executes a PowerShell script. This script:

Downloads an executable masquerading as vlc.exe into C:\Windows\Tasks\lama . Retrieves a DLL named libvlc.dll to side-load with vlc.exe. Fetches a decoy PDF from a malicious URL and places it in the Public Documents folder. Creates a scheduled task called WindowsErrorReport to trigger vlc.exe regularly. Downloads and saves the APT’s final payload, a .NET-based executable compiled with MSIL.

Once vlc.exe is launched, the loader’s fStage method initiates communication with the attacker’s C2 server. It gathers system information and performs the following:

XORs the client ID with a hardcoded key and Base64-encodes the result. Applies obfuscation via a custom Protean function. Sends data over HTTPS using TLS 1.2 as a POST form.

The server response is decoded and decrypted to produce a session key. If the fStage fails, retries occur every five seconds, up to twenty attempts.

This loader exploits Windows Scheduled Tasks to execute its final payload.
Heather Lyons · Thehackingpost

Subsequently, the SStage method inventories the host:

Public IP. OS version. MAC address and username. Working directory path. Process ID and administrative privilege status. Unique session ID.

Data is obfuscated and transmitted. Simultaneously, the bkj method launches:

dsffds() collects installed applications via WMI. ghjk() enumerates antivirus products.

The _getCommand function retrieves attacker instructions disguised as legitimate web form POSTs. Execution results are sent back to the C2 server using the _sendResult method.

Advertisement

Responses undergo deobfuscation and decryption to yield plaintext commands. Failures trigger retry loops to maintain stealth.

For exfiltration, command outputs are encoded and sent with a unique victim ID. Retries ensure reliable delivery.

dfile : Downloads and decodes auxiliary files. ufile : Streams large files to the C2 in segments. v_alloc : Executes in-memory code. scrt : Captures and uploads screenshots.

To counter Patchwork’s approach, robust endpoint defenses are critical. Enabling macros only from trusted sources, monitoring scheduled tasks, and enforcing application whitelisting can disrupt the loader’s execution chain.

Deploying security solutions with up-to-date signatures and behavior-based detection can identify these techniques before data exfiltration occurs. Regular updates to operating systems and security software are essential.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories