Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
2026-06-17T19:23:46Z•fe73e84708710a77d60100f397401101b872977b47ae311ef97bc9cdb93a6c77
C2CVE-2026-35273DLL side-loadingDonutDropping ElephantFondue.exeIOCsOracle PeopleSoftRATbehavioral detectioncontrol-flow flatteningfilelessin-memorymalwarepatchingremote code executionruntime API reconstructionthreat-huntingzero-day
What happened
Rapid7 researchers tracked a sophisticated Dropping Elephant campaign that uses a China-themed decoy to deliver a heavily reworked, in-memory remote access trojan (RAT). The chain employs DLL side‑loading of a legitimate Microsoft binary (Fondue.exe) and "Donut" shellcode to map the RAT into memory, with additional evasion like control‑flow flattening, runtime API reconstruction, and hardened C2. Rapid7 emphasizes behavior-based detection (memory visibility, threat hunting) over IOCs: notable behaviors include shortcut files spawning PowerShell, files staged in C:\Users\Public\, and the use of
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- fe73e84708710a77d60100f397401101b872977b47ae311ef97bc9cdb93a6c77
- Enrichment time
- 2026-06-17T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.