Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT
ID: 4095794b-8b5e-5928-8a39-fd2dfc084132
STIX ID: report--4095794b-8b5e-5928-8a39-fd2dfc084132
Feed Name: GBHackers
A Rapid7-style analysis attributes a sophisticated China-themed campaign to the actor “Dropping Elephant” that uses an LNK-triggered PowerShell downloader, staged artifacts in C:\Users\Public, DLL side-loading via Fondue.exe and a malicious APPWIZ.cpl which decrypts a Donut shellcode to map an in-memory RAT; the implant patches AMSI/WLDP/ETW, beacons over HTTPS with a Salsa20 envelope and a 23-character token to C2 domains, and offers reconnaissance and remote-control capabilities—the report provides TTPs, detection guidance (e.g., high-frequency scheduled task named GoogleErrorReport, Fondue.exe loading APPWIZ.cpl from nonstandard paths), and a set of IOCs (SHA-256 hashes and filenames).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
