How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

calendar_today June 17, 2026 person Anna Širokova domain rapid7

Executive summary Rapid7 researchers have identified a sophisticated malware campaign attributed to the threat actor “Dropping Elephant,” characterized by the use of a China-themed decoy document to deliver a heavily reworked, in-memory remote access trojan (RAT). This campaign demonstrates advanced evasion techniques, including DLL side-loading with a legitimate Microsoft binary ( Fondue.exe ) and the use of “Donut” shellcode to map the RAT directly into memory, effectively bypassing traditiona

open_in_new Read original post