Socprime Dropping Elephant Malware Campaign Utilizes China-Themed Loader Chain
Article Content
- •Dropping Elephant uses China-themed documents to deliver a sophisticated RAT.
- •The malware employs advanced evasion techniques like DLL side-loading and in-memory execution.
- •Defenders should focus on behavioral detections and memory-level visibility to combat this threat.
Rapid7 identified a sophisticated malware campaign attributed to the threat actor 'Dropping Elephant,' leveraging China-themed decoy documents to deliver a revamped in-memory remote access trojan (RAT). The attack employs advanced evasion techniques, including DLL side-loading using a legitimate Microsoft binary (Fondue.exe) and the Donut shellcode loader, to avoid detection by traditional security measures. The campaign was uncovered during a proactive threat hunt that began with a malicious Windows shortcut masquerading as a PDF document. The final payload is characterized by control-flow flattening and runtime API reconstruction, complicating detection efforts. Key behaviors for defenders to monitor include suspicious shortcut files, unusual scheduled tasks, and payload staging in C:\Users\Public. The infrastructure associated with this actor is actively being monitored by Rapid7 to provide intelligence and protection to customers. The campaign's complexity highlights the need for enhanced memory-level visibility and proactive threat hunting.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Dropping Elephant in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…