Skip to content
Dropping Elephant Malware Campaign Utilizes China-Themed Loader Chain

Dropping Elephant Malware Campaign Utilizes China-Themed Loader Chain

First seen 19 Jun 2026, 16:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 20, 2026 at 16:52 UTC
  • Dropping Elephant uses China-themed documents to deliver a sophisticated RAT.
  • The malware employs advanced evasion techniques like DLL side-loading and in-memory execution.
  • Defenders should focus on behavioral detections and memory-level visibility to combat this threat.

Rapid7 identified a sophisticated malware campaign attributed to the threat actor 'Dropping Elephant,' leveraging China-themed decoy documents to deliver a revamped in-memory remote access trojan (RAT). The attack employs advanced evasion techniques, including DLL side-loading using a legitimate Microsoft binary (Fondue.exe) and the Donut shellcode loader, to avoid detection by traditional security measures. The campaign was uncovered during a proactive threat hunt that began with a malicious Windows shortcut masquerading as a PDF document. The final payload is characterized by control-flow flattening and runtime API reconstruction, complicating detection efforts. Key behaviors for defenders to monitor include suspicious shortcut files, unusual scheduled tasks, and payload staging in C:\Users\Public. The infrastructure associated with this actor is actively being monitored by Rapid7 to provide intelligence and protection to customers. The campaign's complexity highlights the need for enhanced memory-level visibility and proactive threat hunting.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-17
Rapid7 identifies Dropping Elephant campaign
Researchers discovered a malware campaign using a China-themed decoy document to deliver a reworked RAT via DLL side-loading.
Rapid7
2026-06-19
Socprime reports on Dropping Elephant's tactics
Socprime highlights the use of a malicious Windows shortcut and advanced evasion methods in the campaign.
Socprime

More articles in this cluster (5)

Following this threat?

Track Dropping Elephant in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed