Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:21:45 UTC APT group: Urpage Names Urpage (Trend Micro) Country [Middle East] Sponsor State-sponsored Motivation Information theft and espionage First seen 2018 Description (Trend Micro) In the process of monitoring changes in the threat landscape, we get a clearer insight into the way threat actors work behind the schemes. In this case we dig deeper into the possible connection between cyberattacks by focusing on the similarities an unnamed threat actor shares with Patchwork, Dropping Elephant, and another threat actor called Bahamut. For the sake of this report, we will call this unnamed threat actor “Urpage.” Observed Countries: Pakistan. Tools used Trojaned Android applications. Information Last change to this card: 15 April 2020 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=894e7bdb-9c99-4021-a673-45ddb9772450 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=894e7bdb-9c99-4021-a673-45ddb9772450 Page 1 of 1