Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

2026-06-17T19:23:46Zfe73e84708710a77d60100f397401101b872977b47ae311ef97bc9cdb93a6c77
C2CVE-2026-35273DLL side-loadingDonutDropping ElephantFondue.exeIOCsOracle PeopleSoftRATbehavioral detectioncontrol-flow flatteningfilelessin-memorymalwarepatchingremote code executionruntime API reconstructionthreat-huntingzero-day

What happened

Rapid7 researchers tracked a sophisticated Dropping Elephant campaign that uses a China-themed decoy to deliver a heavily reworked, in-memory remote access trojan (RAT). The chain employs DLL side‑loading of a legitimate Microsoft binary (Fondue.exe) and "Donut" shellcode to map the RAT into memory, with additional evasion like control‑flow flattening, runtime API reconstruction, and hardened C2. Rapid7 emphasizes behavior-based detection (memory visibility, threat hunting) over IOCs: notable behaviors include shortcut files spawning PowerShell, files staged in C:\Users\Public\, and the use of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
fe73e84708710a77d60100f397401101b872977b47ae311ef97bc9cdb93a6c77
Enrichment time
2026-06-17T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.