logo

Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT

ID: 4095794b-8b5e-5928-8a39-fd2dfc084132

STIX ID: report--4095794b-8b5e-5928-8a39-fd2dfc084132

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Mayura Kathir

...
...

A Rapid7-style analysis attributes a sophisticated China-themed campaign to the actor “Dropping Elephant” that uses an LNK-triggered PowerShell downloader, staged artifacts in C:\Users\Public, DLL side-loading via Fondue.exe and a malicious APPWIZ.cpl which decrypts a Donut shellcode to map an in-memory RAT; the implant patches AMSI/WLDP/ETW, beacons over HTTPS with a Salsa20 envelope and a 23-character token to C2 domains, and offers reconnaissance and remote-control capabilities—the report provides TTPs, detection guidance (e.g., high-frequency scheduled task named GoogleErrorReport, Fondue.exe loading APPWIZ.cpl from nonstandard paths), and a set of IOCs (SHA-256 hashes and filenames).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.