Threat reportMalwareTL-2026-0838
Dropping Elephant (Patchwork / APT-C-09) China-Themed Energy-Sector Loader Chain Delivering Memory-Resident Salsa20 RAT
Dropping Elephant (Patchwork / APT-C-09) China-Themed (TL-2026-0838), also tracked as GRES-3 Energy Lure Campaign, is a high-severity malware campaign, first published 2026-06-17. It is attributed to Patchwork (India) with high confidence, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1Patchwork
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-0838
- Threat ID
- TL-2026-0838
- Also known as
- GRES-3 Energy Lure Campaign, China-Themed Loader Chain
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Patchwork
- Attribution confidence
- HIGH
- Nation-state nexus
- India
- Motivation
- ESPIONAGE
- Target sectors
- energy, defense, government, diplomatic
- Target regions
- South Asia, East Asia
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Dropping Elephant (Patchwork / APT-C-09) China-Themed
Malware and tooling: Dropping Elephant RAT
How Dropping Elephant (Patchwork / APT-C-09) China-Themed works
Rapid7 tracked an active Dropping Elephant (Patchwork) campaign using a China-themed energy-contract lure (GRES-3 industrial seawater pump project) delivered via a malicious LNK that chains obfuscated PowerShell, DLL side-loading through APPWIZ.cpl, an AES-256-CBC-decrypted Donut loader, and a fully memory-resident 32-bit C++ RAT. The reworked implant adds control-flow flattening, opaque predicates, and Salsa20-encrypted HTTPS C2 while retaining recognizable Dropping Elephant beaconing, screenshot, and command-handler patterns confirmed via Diaphora function overlap with a July 2025 Arctic Wolf sample.
In June 2026 Rapid7 Labs documented a Dropping Elephant (a.k.a. Patchwork, APT-C-09, Quilted Tiger, Monsoon, Operation Hangover; MITRE G0040) intrusion set delivering a reworked memory-resident remote access trojan to energy-sector targets using a China-themed decoy. The attack opens with a malicious Windows shortcut, GRES3001.lnk, masquerading as a PDF and themed around the GRES-3 industrial seawater circulation pump procurement project. When opened, the LNK spawns obfuscated PowerShell through conhost.exe using basic string-splitting evasion (e.g. iw''r, g''c''i, r''e''n, c''p''i) that retrieves a staged payload set from chinagreenenergy[.]org.
The downloaded files arrive with junk extensions (.ezxzez, .cypyly, .dzlzlz) and are renamed into C:\Users\Public\: a legitimate Microsoft binary Fondue.exe, a malicious loader APPWIZ.cpl (internal metadata bluetooth_callback.dll, export RunFODW), the VC++ runtimes msvcp140.dll and vcruntime140.dll, and an AES-256-CBC-encrypted blob editor.dat staged in C:\Windows\Tasks\. Persistence is established with a scheduled task named GoogleErrorReport that runs Fondue.exe every minute. Fondue.exe side-loads the malicious APPWIZ.cpl from the non-standard C:\Users\Public\ directory (DLL side-loading), and APPWIZ.cpl decrypts editor.dat via Windows CNG (bcrypt.dll) AES-256-CBC using a hardcoded 32-byte key and 16-byte IV, transferring control to a Donut shellcode blob through an EnumUILanguagesW callback.
The Donut loader protects its embedded PE with Chaskey-CTR and patches AMSI, WLDP, and ETW before reflectively loading the final 32-bit native C++ implant entirely in memory. The RAT registers to operational C2 gcl-power[.]org over HTTPS/443, gating traffic with token RRn926EmIRfm9IlJyP1yVO2 and submitting a Salsa20-encrypted, base64url-wrapped registration beacon carrying username, computer name, runtime-derived bot ID, OS version, public IP, and country (resolved via api.ipify[.]org and ip2c[.]org) plus the full process list. Salsa20 uses key tn9905083tfbsxqrxs7qe4ryw1nif8h1 with nonce lPvymwIk; check-in cadence is every 10 seconds with 2-second retry, and an idle sentinel MMMMM==YYYYY indicates no tasking. Command handlers support directory listing (fl), download-and-execute (dw), screenshot via BitBlt/WIC (sc), shell execution (cmx), and file upload/exfiltration (uf). Anti-analysis tradecraft includes control-flow flattening, opaque predicates, dynamic API resolution, stack-built strings, static CRT linking, process blacklist checks, CPUID hypervisor checks, and VM artifact checks. Rapid7 attributed the campaign to Dropping Elephant through Diaphora function-level overlap (four shared functions) with reference sample 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2 documented by Arctic Wolf in July 2025 against the Turkish defense industry; BinDiff scored only 8.6% similarity, discounted due to control-flow flattening. No CVE is involved.
MITRE ATT&CK techniques used in TL-2026-0838
Collection
T1005 Data from Local System; T1113 Screen Capture
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1614 System Location Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1497.001 System Checks; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography
Initial Access
T1566.001 Spearphishing Attachment
stealth
defense-impairment
Affected products and versions in Dropping Elephant (Patchwork / APT-C-09) China-Themed
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server
Remediation for Dropping Elephant (Patchwork / APT-C-09) China-Themed
Immediate actions
- Block C2 and staging domains gcl-power.org and chinagreenenergy.org at DNS/perimeter
- Hunt for scheduled task named GoogleErrorReport executing Fondue.exe every minute
- Hunt for Fondue.exe loading APPWIZ.cpl from C:\Users\Public\ rather than a Windows system directory
- Quarantine files staged in C:\Users\Public\ (Fondue.exe, APPWIZ.cpl) and C:\Windows\Tasks\editor.dat matching listed hashes
Workarounds
- Disable execution of .cpl files from non-system paths via application control
- Apply LNK and Office attachment filtering at the email gateway
Longer-term hardening
- Deploy EDR with in-memory/behavioral detection for AMSI/WLDP/ETW tampering
- Restrict and monitor execution of files from C:\Users\Public\
- Block or alert on Windows shortcuts (.lnk) that spawn PowerShell via conhost.exe
- Enforce PowerShell script-block and module logging to catch string-splitting obfuscation
Timeline of Dropping Elephant (Patchwork / APT-C-09) China-Themed
- Dropping Elephant / Patchwork (APT-C-09, G0040) active as a suspected India-linked espionage group targeting foreign-policy, defense, diplomatic and academic entities across South and East Asia.
- Kaspersky GReAT publicly documented the espionage group as 'Dropping Elephant' (a.k.a. Chinastrats); Symantec independently named the same intrusion set 'Patchwork' the same year, noting heavy reliance on copy-pasted/repurposed code and decoy-document lures.
- Forcepoint detailed the MONSOON cyber-espionage campaign, later linked to Patchwork, using malicious documents and a long-running infrastructure set against government and military targets.
- MITRE ATT&CK catalogued the group as Patchwork (G0040), formalizing its documented techniques including spearphishing, scheduled-task persistence, and DLL side-loading.
- Arctic Wolf observed Dropping Elephant infrastructure preparation beginning, ahead of operations against the Turkish defense industry.
- Arctic Wolf documented the reference RAT sample (SHA-256 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2) against Turkish defense contractors; later used as the lineage anchor for the 2026 variant.
- Rapid7 Labs published 'Tracking Dropping Elephant Tradecraft: China-Themed Loader Chain Delivering Memory-Resident RAT' with full IOCs and ATT&CK mapping.
- Rapid7 confirmed Dropping Elephant lineage via Diaphora function-level overlap (four shared functions); BinDiff scored 8.6% similarity, discounted due to control-flow flattening.
- Staging domain chinagreenenergy.org and operational C2 gcl-power.org observed active during Rapid7 analysis of the China-themed energy loader chain.
Sources cited for Dropping Elephant (Patchwork / APT-C-09) China-Themed
- Tracking Dropping Elephant Tradecraft: China-Themed Loader Chain Delivering Memory-Resident RAT
- Dropping Elephant APT Group Targets Turkish Defense Industry: LOLBAS, VLC Player, and Encrypted Shellcode
- Patchwork, Hangover Group, Dropping Elephant, MONSOON, Operation Hangover (G0040)
- Dark Web Profile: Patchwork APT
- A Deep Dive Into Patchwork APT Group
- MONSOON Cyber-Espionage Campaign Linked to Patchwork APT
- QUILTED TIGER (Threat Actor) - Malpedia
Detection coverage for TL-2026-0838
As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0838 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.