Rapid7 reported a renewed Dropping Elephant malware campaign using a China-themed lure to deliver a heavily reworked, memory-resident remote access trojan on Windows systems. Victims are enticed with a decoy document tied to a GRES-3 seawater pump contract, while a malicious shortcut file, GRES3001.lnk, launches a PowerShell-based staging chain that downloads components from chinagreenenergy[.]org. The malware then abuses the legitimate Microsoft binary Fondue.exe to side-load a malicious APPWIZ.cpl file from C:\Users\Public\, decrypts an AES-256-CBC protected payload from editor.dat, and uses Donut shellcode to map the final 32-bit RAT directly into memory.
The RAT patches AMSI, WLDP, and ETW in-process to reduce detection, then communicates over encrypted HTTPS with gcl-power[.]org using Salsa20-protected fields and frequent beaconing. Rapid7 said the malware supports host fingerprinting, process enumeration, directory listing, file upload, download-and-execute, shell execution, and screenshot capture, while persistence is maintained through a scheduled task named GoogleErrorReport that runs Fondue.exe every minute from C:\Users\Public\. Researchers linked the activity to earlier Dropping Elephant tooling through shared command-handler structure, screenshot logic, WININET request flow, and beaconing patterns, and urged defenders to focus on behavioral detections such as LNK-triggered PowerShell, nonstandard Fondue.exe loading of APPWIZ.cpl, and the GoogleErrorReport task rather than static indicators alone.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Rapid7 identified a malware campaign attributed to Dropping Elephant that uses a China-themed decoy document and a malicious Windows shortcut to deliver a heavily reworked, memory-resident remote access trojan. The chain uses PowerShell staging, DLL side-loading via Fondue.exe, and persistence through a scheduled task named GoogleErrorReport.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.