CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 372

As cited

Copy frozen at (site build).

threat intel

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

Rapid7 researchers identified a sophisticated malware campaign attributed to Dropping Elephant using a China-themed decoy document to deliver a heavily modified remote access trojan (RAT). The attack chain employs advanced evasion techniques including DLL side-loading with the legitimate Microsoft binary Fondue.exe, Donut shellcode for in-memory payload execution, and hardened command and control (C2) communications to bypass traditional security controls. Despite significant code modifications, the researchers confirmed the campaign represents an evolution of Dropping Elephant's tradecraft through analysis of shared beaconing patterns, command structures, and screenshot capture logic.

Why it matters: Defenders need memory-level visibility and behavioral detection to identify this campaign, since the final payload never touches disk and traditional file-based indicators of compromise are ineffective.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

Rapid7 researchers identified a sophisticated malware campaign attributed to Dropping Elephant using a China-themed decoy document to deliver a heavily modified remote access trojan (RAT). The attack chain employs advanced evasion techniques including DLL side-loading with the legitimate Microsoft binary Fondue.exe, Donut shellcode for in-memory payload execution, and hardened command and control (C2) communications to bypass traditional security controls. Despite significant code modifications, the researchers confirmed the campaign represents an evolution of Dropping Elephant's tradecraft through analysis of shared beaconing patterns, command structures, and screenshot capture logic.

Why it matters: Defenders need memory-level visibility and behavioral detection to identify this campaign, since the final payload never touches disk and traditional file-based indicators of compromise are ineffective.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary