HOMETHREATSQUILTED TIGER
APT / THREAT GROUP🕵️ ESPIONAGE

QUILTED TIGER

🇮🇳India-attributed
1
campaigns
12
aliases
Last seen:Mar 17, 2026

Intelligence Profile

Dropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and economic targets using a custom set of attack tools. Its victims are all involved with China’s foreign relations in some way, and are generally caught through spear-phishing or watering hole attacks.

Threat Analysis

QUILTED TIGER is a known-sophistication threat actor attributed to India, engaged in cyber operations with a primary motivation of espionage.

The group's espionage-oriented operations suggest a state-sponsored or state-aligned mandate, typically focused on stealing intellectual property, government secrets, or military intelligence. Targets are usually selected for strategic value rather than financial gain.

Known Campaigns

QUILTED TIGER — Active Operations March 2026

QUILTED TIGER is a unknown-motivation threat actor attributed to IN. Dropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and economic targets using a custom set of attack tools. Its victims are all involved with China’s foreign relations in some way...

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Motivation🕵️ espionage
Origin🇮🇳 India
Aliases12
SourceMalpedia

Also Known As

PatchworkAPT-C-09ZINC EMERSONSaritThirsty GeminiATK11ChinastratsQUILTED TIGERG0040Dropping ElephantOrange AthosMonsoon

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.