Dropping Elephant Malware: China-Themed Loader Campaign Analyzed
ID: d50bd29f-7adb-5ad2-8bbc-2599c6f05f89
STIX ID: report--d50bd29f-7adb-5ad2-8bbc-2599c6f05f89
Feed Name: securityonline.info
Rapid7 researchers describe a Dropping Elephant campaign that uses China-themed malicious Windows LNK shortcuts to trigger obfuscated scripts, download decoy documents and stage a multi-stage fileless infection. The chain side-loads a malicious library, decrypts shellcode in-memory and unpacks a memory-resident RAT capable of process enumeration, screenshot capture, HTTPS-based C2 and exfiltration; the report targets suspected Asian energy-sector entities and provides behavioral detection recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
