Dropping Elephant (Patchwork / APT-C-09) China-Themed Energy-Sector Loader Chain Delivering Memory-Resident Salsa20 RAT — Threadlinqs Intelligence
As of 2026-06-17, Dropping Elephant (Patchwork / APT-C-09) China-Themed Energy-Sector Loader Chain Delivering Memory-Resident Salsa20 RAT is a high-severity malware threat attributed to Patchwork (India), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0838 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Patchwork · India · ESPIONAGE
Rapid7 tracked an active Dropping Elephant (Patchwork) campaign using a China-themed energy-contract lure (GRES-3 industrial seawater pump project) delivered via a malicious LNK that chains obfuscated
In June 2026 Rapid7 Labs documented a Dropping Elephant (a.k.a. Patchwork, APT-C-09, Quilted Tiger, Monsoon, Operation Hangover; MITRE G0040) intrusion set delivering a reworked memory-resident remote access trojan to energy-sector targets using a China-themed decoy. The attack opens with a malicious Windows shortcut, GRES3001.lnk, masquerading as a PDF and themed around the GRES-3 industrial seawater circulation pump procurement project. When opened, the LNK spawns obfuscated PowerShell through conhost.exe using basic string-splitting evasion (e.g. iw''r, g''c''i, r''e''n, c''p''i) that retrieves a staged payload set from chinagreenenergy[.]org.
The downloaded files arrive with junk extensions (.ezxzez, .cypyly, .dzlzlz) and are renamed into C:\Users\Public\: a legitimate Microsoft binary Fondue.exe, a malicious loader APPWIZ.cpl (internal metadata bluetooth_callback.dll, export RunFODW), the VC++ runtimes msvcp140.dll and vcruntime140.dll, and an AES-256-CBC-encrypted blob editor.dat staged in C:\Windows\Tasks\. Persistence is established with a scheduled task named GoogleErrorReport that runs Fondue.exe every minute. Fondue.exe side-loads the malicious APPWIZ.cpl from the non-standard C:\Users\Public\ directory (DLL side-loading), and APPWIZ.cpl decrypts editor.dat via Windows CNG (bcrypt.dll) AES-256-CBC using a hardcoded 32-byte key and 16-byte IV, transferring control to a Donut shellcode blob through an EnumUILanguagesW callback.
The Donut loader protects its embedded PE with Chaskey-CTR and patches AMSI, WLDP, and ETW before reflectively loading the final 32-bit native C++ implant entirely in memory. The RAT registers to operational C2 gcl-power[.]org over HTTPS/443, gating traffic with token RRn926EmIRfm9IlJyP1yVO2 and submitting a Salsa20-encrypted, base64url-wrapped registration beacon carrying username, computer name, runtime-derived bot ID, OS version, public IP, and country (resolved via api.ipify[.]org and ip2c[.]org) plus the full process list. Salsa20 uses key tn9905083tfbsxqrxs7qe4ryw1nif8h1 with nonce lPvymwIk; check-in cadence is every 10 seconds with 2-second retry, and an idle sentinel MMMMM==YYYYY indicates no tasking. Command handlers support directory listing (fl), download-and-execute (dw), screenshot via BitBlt/WIC (sc), shell execution (cmx), and file upload/exfiltration (uf). Anti-analysis tradecraft includes control-flow flattening, opaque predicates, dynamic API resolution, stack-built strings, static CRT linking, process blacklist checks, CPUID hypervisor checks, and VM artifact checks. Rapid7 attributed the campaign to Dropping Elephant through Diaphora function-level overlap (four shared functions) with reference sample 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2 documented by Arctic Wolf in July 2025 against the Turkish defense industry; BinDiff scored only 8.6% similarity, discounted due to control-flow flattening. No CVE is involved.
Target sectors: energy, defense, government, diplomatic
Target regions: South Asia, East Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1204.002, T1059.001, T1059.003, T1053.005, T1574.002, T1036.005, T1027, T1620, T1562.001