Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT
ID: b3f5d342-f1e3-5cae-83d2-918fb0c2ea85
STIX ID: report--b3f5d342-f1e3-5cae-83d2-918fb0c2ea85
Feed Name: GBHackers
TrendAI tracked a sophisticated malvertising campaign (Apr 8–Jun 14, 2026) that used Google Ads to lure AI developer users to weaponized GitLab Pages and claude.ai shared chats; the pages delivered ClickFix-style copy-paste commands that fetched a multi-stage, China-themed loader which executed a Mac infostealer and an in-memory RAT, enabling stealthy remote access. The operators rotated 106 hostnames across six waves, targeted the Asia-Pacific region (≈67% of victims), and exploited high-reputation platforms to evade URL/certificate-based defenses; TrendAI recommends disabling unsafe copy-paste execution, implementing script-blocking and shell command inspection, and monitoring for in-memory RAT indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
