Dropping Elephant India-Linked Hackers Target Missile Firm in Sophisticated Cyber Espionage
2025 has seen a dramatic escalation in nation-state cyber threats, with “Dropping Elephant” an India-linked APT group (also known as Patchwork) spearheading a highly targeted campaign against Türkiye’s defense sector.

Inside Operation Dropping Elephant: India-Linked Hackers Target Turkish Missile Firm in Sophisticated Cyber Espionage
2025 has seen a dramatic escalation in nation-state cyber threats, with “Dropping Elephant” an India-linked APT group (also known as Patchwork) spearheading a highly targeted campaign against Türkiye’s defense sector. Their latest operation, aimed at a leading Turkish precision-guided missile manufacturer, exploited a mix of advanced tactics and social engineering to breach vital R&D infrastructure.
How Did the Attack Happen?
The breach began with convincing spear-phishing emails disguised as invites to an international unmanned vehicle systems conference. These lures contained weaponized shortcut (LNK) files, harboring a five-stage payload chain that leveraged legitimate applications such as VLC Media Player and Microsoft Task Scheduler (a technique known as DLL side-loading) for stealthy malware delivery and persistence in the network.
The attackers used well-known living-off-the-land binaries and staged downloads to reduce detection and increase operational security. They mimicked trusted organizations including Türkiye’s own Pardus Linux distribution using typosquat domains like rosereserve.org and roseserve.org, and hosted command-and-control (C2) infrastructure on servers deliberately obfuscated behind international VPS providers. All these measures indicate patient, methodical operational planning.
Why Is This Attack Significant?
Technical Evolution: The group has refined its malware, moving from x64 DLLs to lighter x86 payloads with more complex command structures and less reliance on external libraries.
Geopolitical Motivation: The targeting aligns with heightened regional cooperation between Türkiye and Pakistan, and concurrent military tensions involving India.
Sector Focus: While once mainly active in Asia, the group now routinely targets defense, energy, financial, and governmental organizations worldwide.
Infrastructure Map and IOCs: What to Block Now
Below are the critical Indicators of Compromise (IOCs) from this attack. Block or monitor these in your organization’s security tools immediately:
| Type | Indicator | Action | Notes |
|---|---|---|---|
| IP Address | 193.140.63.90 | Block / Monitor | Potential malicious IP |
| IP Address | 2.56.127.187 | Block / Monitor | Potential malicious IP |
| Domain | rosereserve.org | Block / Sinkhole | Phishing/C2 domain |
| Domain | roseserve.org | Block / Sinkhole | Typosquat of above domain |
| File Hash (MD5) | 01b12fc6509c7b431e3ee7142dbdb1bd | Block / Flag in AV | Malware sample hash (MD5) |
| File Hash (MD5) | 01600b4f79b096111a096435b82378ac | Block / Flag in AV | Malware sample hash (MD5) |
| File Hash (SHA-256) | 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2 | Block / Flag in AV | Malware sample hash (SHA-256) |
What Can You Do?
Patch and Educate: Social engineering is at the core of these attacks. Make sure your staff is trained to spot phishing attempts, and always keep your software up-to-date to avoid exploitation through old vulnerabilities.
Strengthen Defenses: Deploy threat intelligence feeds, respond quickly to alerts, and use endpoint detection and response (EDR) solutions to stop lateral movement and data theft.
Review Supply Chain Risks: Even non-technical partners can be vectors for highly targeted campaigns.



