Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
2026-06-18T07:23:45Z•dabcc0cfa9c28b185731a02ba36c29e969f038927f63e78394b81956c37ec3f0
API reconstructionC2C:\Users\Public\DLL side‑loadingDonutDropping ElephantFondue.exeIOCPowerShellRATbeaconingcontrol‑flow flatteningfilelessin‑memorymalwarememory forensicspersistencescheduled taskshellcodethreat hunting
What happened
Rapid7 details an advanced Dropping Elephant malware campaign that uses a China-themed decoy to deliver a heavily reworked, in-memory remote access trojan (RAT). The chain abuses DLL side‑loading of a legitimate Microsoft binary (Fondue.exe) and uses Donut shellcode to map the RAT directly into memory, plus multiple hardening/evasion techniques (control‑flow flattening, runtime API reconstruction, stealthy C2). Rapid7 recommends focusing on behavioral detection and memory‑level visibility (e.g., shortcut spawning PowerShell, files staged in C:\Users\Public\, suspicious scheduled tasks) rather
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- dabcc0cfa9c28b185731a02ba36c29e969f038927f63e78394b81956c37ec3f0
- Enrichment time
- 2026-06-18T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.