Dropping Elephant Malware Campaign Utilizes China-Themed Loader Chain

Dropping Elephant Malware Campaign Utilizes China-Themed Loader Chain

First seen 19 Jun 2026, 16:52 UTC Rapid7SocprimeGbhackerswww.rapid7.com 83% similarity 69.5

Article Content

Browse articles
ThreatCluster

Rapid7 identified a sophisticated malware campaign attributed to the threat actor 'Dropping Elephant,' leveraging China-themed decoy documents to deliver a revamped in-memory remote access trojan (RAT). The attack employs advanced evasion techniques, including DLL side-loading using a legitimate Microsoft binary (Fondue.exe) and the Donut shellcode loader, to avoid detection by traditional security measures. The campaign was uncovered during a proactive threat hunt that began with a malicious Windows shortcut masquerading as a PDF document. The final payload is characterized by control-flow flattening and runtime API reconstruction, complicating detection efforts. Key behaviors for defenders to monitor include suspicious shortcut files, unusual scheduled tasks, and payload staging in C:\Users\Public. The infrastructure associated with this actor is actively being monitored by Rapid7 to provide intelligence and protection to customers. The campaign's complexity highlights the need for enhanced memory-level visibility and proactive threat hunting.

Key Points: • Dropping Elephant uses China-themed documents to deliver a sophisticated RAT. • The malware employs advanced evasion techniques like DLL side-loading and in-memory execution. • Defenders should focus on behavioral detections and memory-level visibility to combat this threat.

ThreatCluster AI How this analysis works

Timeline

2026-06-17
Rapid7 identifies Dropping Elephant campaign
Researchers discovered a malware campaign using a China-themed decoy document to deliver a reworked RAT via DLL side-loading.
Rapid7
2026-06-19
Socprime reports on Dropping Elephant's tactics
Socprime highlights the use of a malicious Windows shortcut and advanced evasion methods in the campaign.
Socprime

Community

Browse all →