Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

2026-06-18T07:23:45Zdabcc0cfa9c28b185731a02ba36c29e969f038927f63e78394b81956c37ec3f0
API reconstructionC2C:\Users\Public\DLL side‑loadingDonutDropping ElephantFondue.exeIOCPowerShellRATbeaconingcontrol‑flow flatteningfilelessin‑memorymalwarememory forensicspersistencescheduled taskshellcodethreat hunting

What happened

Rapid7 details an advanced Dropping Elephant malware campaign that uses a China-themed decoy to deliver a heavily reworked, in-memory remote access trojan (RAT). The chain abuses DLL side‑loading of a legitimate Microsoft binary (Fondue.exe) and uses Donut shellcode to map the RAT directly into memory, plus multiple hardening/evasion techniques (control‑flow flattening, runtime API reconstruction, stealthy C2). Rapid7 recommends focusing on behavioral detection and memory‑level visibility (e.g., shortcut spawning PowerShell, files staged in C:\Users\Public\, suspicious scheduled tasks) rather

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
dabcc0cfa9c28b185731a02ba36c29e969f038927f63e78394b81956c37ec3f0
Enrichment time
2026-06-18T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.