logo

Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT

ID: b3f5d342-f1e3-5cae-83d2-918fb0c2ea85

STIX ID: report--b3f5d342-f1e3-5cae-83d2-918fb0c2ea85

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

TrendAI tracked a sophisticated malvertising campaign (Apr 8–Jun 14, 2026) that used Google Ads to lure AI developer users to weaponized GitLab Pages and claude.ai shared chats; the pages delivered ClickFix-style copy-paste commands that fetched a multi-stage, China-themed loader which executed a Mac infostealer and an in-memory RAT, enabling stealthy remote access. The operators rotated 106 hostnames across six waves, targeted the Asia-Pacific region (≈67% of victims), and exploited high-reputation platforms to evade URL/certificate-based defenses; TrendAI recommends disabling unsafe copy-paste execution, implementing script-blocking and shell command inspection, and monitoring for in-memory RAT indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.