Threat reportMalwareTL-2026-0838

Dropping Elephant (Patchwork / APT-C-09) China-Themed Energy-Sector Loader Chain Delivering Memory-Resident Salsa20 RAT

highACTIVE

Dropping Elephant (Patchwork / APT-C-09) China-Themed (TL-2026-0838), also tracked as GRES-3 Energy Lure Campaign, is a high-severity malware campaign, first published 2026-06-17. It is attributed to Patchwork (India) with high confidence, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
1Patchwork
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-0838

Threat ID
TL-2026-0838
Also known as
GRES-3 Energy Lure Campaign, China-Themed Loader Chain
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Patchwork
Attribution confidence
HIGH
Nation-state nexus
India
Motivation
ESPIONAGE
Target sectors
energy, defense, government, diplomatic
Target regions
South Asia, East Asia
Detection rules
9
Indicators of compromise
30

Malware and tooling in Dropping Elephant (Patchwork / APT-C-09) China-Themed

Malware and tooling: Dropping Elephant RAT

How Dropping Elephant (Patchwork / APT-C-09) China-Themed works

Rapid7 tracked an active Dropping Elephant (Patchwork) campaign using a China-themed energy-contract lure (GRES-3 industrial seawater pump project) delivered via a malicious LNK that chains obfuscated PowerShell, DLL side-loading through APPWIZ.cpl, an AES-256-CBC-decrypted Donut loader, and a fully memory-resident 32-bit C++ RAT. The reworked implant adds control-flow flattening, opaque predicates, and Salsa20-encrypted HTTPS C2 while retaining recognizable Dropping Elephant beaconing, screenshot, and command-handler patterns confirmed via Diaphora function overlap with a July 2025 Arctic Wolf sample.

In June 2026 Rapid7 Labs documented a Dropping Elephant (a.k.a. Patchwork, APT-C-09, Quilted Tiger, Monsoon, Operation Hangover; MITRE G0040) intrusion set delivering a reworked memory-resident remote access trojan to energy-sector targets using a China-themed decoy. The attack opens with a malicious Windows shortcut, GRES3001.lnk, masquerading as a PDF and themed around the GRES-3 industrial seawater circulation pump procurement project. When opened, the LNK spawns obfuscated PowerShell through conhost.exe using basic string-splitting evasion (e.g. iw''r, g''c''i, r''e''n, c''p''i) that retrieves a staged payload set from chinagreenenergy[.]org.

The downloaded files arrive with junk extensions (.ezxzez, .cypyly, .dzlzlz) and are renamed into C:\Users\Public\: a legitimate Microsoft binary Fondue.exe, a malicious loader APPWIZ.cpl (internal metadata bluetooth_callback.dll, export RunFODW), the VC++ runtimes msvcp140.dll and vcruntime140.dll, and an AES-256-CBC-encrypted blob editor.dat staged in C:\Windows\Tasks\. Persistence is established with a scheduled task named GoogleErrorReport that runs Fondue.exe every minute. Fondue.exe side-loads the malicious APPWIZ.cpl from the non-standard C:\Users\Public\ directory (DLL side-loading), and APPWIZ.cpl decrypts editor.dat via Windows CNG (bcrypt.dll) AES-256-CBC using a hardcoded 32-byte key and 16-byte IV, transferring control to a Donut shellcode blob through an EnumUILanguagesW callback.

The Donut loader protects its embedded PE with Chaskey-CTR and patches AMSI, WLDP, and ETW before reflectively loading the final 32-bit native C++ implant entirely in memory. The RAT registers to operational C2 gcl-power[.]org over HTTPS/443, gating traffic with token RRn926EmIRfm9IlJyP1yVO2 and submitting a Salsa20-encrypted, base64url-wrapped registration beacon carrying username, computer name, runtime-derived bot ID, OS version, public IP, and country (resolved via api.ipify[.]org and ip2c[.]org) plus the full process list. Salsa20 uses key tn9905083tfbsxqrxs7qe4ryw1nif8h1 with nonce lPvymwIk; check-in cadence is every 10 seconds with 2-second retry, and an idle sentinel MMMMM==YYYYY indicates no tasking. Command handlers support directory listing (fl), download-and-execute (dw), screenshot via BitBlt/WIC (sc), shell execution (cmx), and file upload/exfiltration (uf). Anti-analysis tradecraft includes control-flow flattening, opaque predicates, dynamic API resolution, stack-built strings, static CRT linking, process blacklist checks, CPUID hypervisor checks, and VM artifact checks. Rapid7 attributed the campaign to Dropping Elephant through Diaphora function-level overlap (four shared functions) with reference sample 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2 documented by Arctic Wolf in July 2025 against the Turkish defense industry; BinDiff scored only 8.6% similarity, discounted due to control-flow flattening. No CVE is involved.

MITRE ATT&CK techniques used in TL-2026-0838

Collection

T1005 Data from Local System; T1113 Screen Capture

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1497.001 System Checks; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography

Initial Access

T1566.001 Spearphishing Attachment

stealth

T1574.001 DLL

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Dropping Elephant (Patchwork / APT-C-09) China-Themed

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server

Remediation for Dropping Elephant (Patchwork / APT-C-09) China-Themed

Immediate actions

  • Block C2 and staging domains gcl-power.org and chinagreenenergy.org at DNS/perimeter
  • Hunt for scheduled task named GoogleErrorReport executing Fondue.exe every minute
  • Hunt for Fondue.exe loading APPWIZ.cpl from C:\Users\Public\ rather than a Windows system directory
  • Quarantine files staged in C:\Users\Public\ (Fondue.exe, APPWIZ.cpl) and C:\Windows\Tasks\editor.dat matching listed hashes

Workarounds

  • Disable execution of .cpl files from non-system paths via application control
  • Apply LNK and Office attachment filtering at the email gateway

Longer-term hardening

  • Deploy EDR with in-memory/behavioral detection for AMSI/WLDP/ETW tampering
  • Restrict and monitor execution of files from C:\Users\Public\
  • Block or alert on Windows shortcuts (.lnk) that spawn PowerShell via conhost.exe
  • Enforce PowerShell script-block and module logging to catch string-splitting obfuscation

Timeline of Dropping Elephant (Patchwork / APT-C-09) China-Themed

  • Dropping Elephant / Patchwork (APT-C-09, G0040) active as a suspected India-linked espionage group targeting foreign-policy, defense, diplomatic and academic entities across South and East Asia.
  • Kaspersky GReAT publicly documented the espionage group as 'Dropping Elephant' (a.k.a. Chinastrats); Symantec independently named the same intrusion set 'Patchwork' the same year, noting heavy reliance on copy-pasted/repurposed code and decoy-document lures.
  • Forcepoint detailed the MONSOON cyber-espionage campaign, later linked to Patchwork, using malicious documents and a long-running infrastructure set against government and military targets.
  • MITRE ATT&CK catalogued the group as Patchwork (G0040), formalizing its documented techniques including spearphishing, scheduled-task persistence, and DLL side-loading.
  • Arctic Wolf observed Dropping Elephant infrastructure preparation beginning, ahead of operations against the Turkish defense industry.
  • Arctic Wolf documented the reference RAT sample (SHA-256 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2) against Turkish defense contractors; later used as the lineage anchor for the 2026 variant.
  • Rapid7 Labs published 'Tracking Dropping Elephant Tradecraft: China-Themed Loader Chain Delivering Memory-Resident RAT' with full IOCs and ATT&CK mapping.
  • Rapid7 confirmed Dropping Elephant lineage via Diaphora function-level overlap (four shared functions); BinDiff scored 8.6% similarity, discounted due to control-flow flattening.
  • Staging domain chinagreenenergy.org and operational C2 gcl-power.org observed active during Rapid7 analysis of the China-themed energy loader chain.

Sources cited for Dropping Elephant (Patchwork / APT-C-09) China-Themed

Detection coverage for TL-2026-0838

As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0838 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats