# Dropping Elephant (Patchwork / APT-C-09) China-Themed Energy-Sector Loader Chain Delivering Memory-Resident Salsa20 RAT

> Rapid7 tracked an active Dropping Elephant (Patchwork) campaign using a China-themed energy-contract lure (GRES-3 industrial seawater pump project) delivered via a malicious LNK that chains obfuscated PowerShell, DLL side-loading through APPWIZ.cpl, an AES-256-CBC-decrypted Donut loader, and a fully memory-resident 32-bit C++ RAT. The reworked implant adds control-flow flattening, opaque predicates, and Salsa20-encrypted HTTPS C2 while retaining recognizable Dropping Elephant beaconing, screenshot, and command-handler patterns confirmed via Diaphora function overlap with a July 2025 Arctic Wolf sample.

- **Published:** 2026-06-17T00:00:00Z
- **Last reviewed:** 2026-06-17T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0838
- **ID:** TL-2026-0838
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Patchwork (India)
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In June 2026 Rapid7 Labs documented a Dropping Elephant (a.k.a. Patchwork, APT-C-09, Quilted Tiger, Monsoon, Operation Hangover; MITRE G0040) intrusion set delivering a reworked memory-resident remote access trojan to energy-sector targets using a China-themed decoy. The attack opens with a malicious Windows shortcut, GRES3001.lnk, masquerading as a PDF and themed around the GRES-3 industrial seawater circulation pump procurement project. When opened, the LNK spawns obfuscated PowerShell through conhost.exe using basic string-splitting evasion (e.g. iw''r, g''c''i, r''e''n, c''p''i) that retrieves a staged payload set from chinagreenenergy[.]org.

The downloaded files arrive with junk extensions (.ezxzez, .cypyly, .dzlzlz) and are renamed into C:\Users\Public\: a legitimate Microsoft binary Fondue.exe, a malicious loader APPWIZ.cpl (internal metadata bluetooth_callback.dll, export RunFODW), the VC++ runtimes msvcp140.dll and vcruntime140.dll, and an AES-256-CBC-encrypted blob editor.dat staged in C:\Windows\Tasks\. Persistence is established with a scheduled task named GoogleErrorReport that runs Fondue.exe every minute. Fondue.exe side-loads the malicious APPWIZ.cpl from the non-standard C:\Users\Public\ directory (DLL side-loading), and APPWIZ.cpl decrypts editor.dat via Windows CNG (bcrypt.dll) AES-256-CBC using a hardcoded 32-byte key and 16-byte IV, transferring control to a Donut shellcode blob through an EnumUILanguagesW callback.

The Donut loader protects its embedded PE with Chaskey-CTR and patches AMSI, WLDP, and ETW before reflectively loading the final 32-bit native C++ implant entirely in memory. The RAT registers to operational C2 gcl-power[.]org over HTTPS/443, gating traffic with token RRn926EmIRfm9IlJyP1yVO2 and submitting a Salsa20-encrypted, base64url-wrapped registration beacon carrying username, computer name, runtime-derived bot ID, OS version, public IP, and country (resolved via api.ipify[.]org and ip2c[.]org) plus the full process list. Salsa20 uses key tn9905083tfbsxqrxs7qe4ryw1nif8h1 with nonce lPvymwIk; check-in cadence is every 10 seconds with 2-second retry, and an idle sentinel MMMMM==YYYYY indicates no tasking. Command handlers support directory listing (fl), download-and-execute (dw), screenshot via BitBlt/WIC (sc), shell execution (cmx), and file upload/exfiltration (uf). Anti-analysis tradecraft includes control-flow flattening, opaque predicates, dynamic API resolution, stack-built strings, static CRT linking, process blacklist checks, CPUID hypervisor checks, and VM artifact checks. Rapid7 attributed the campaign to Dropping Elephant through Diaphora function-level overlap (four shared functions) with reference sample 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2 documented by Arctic Wolf in July 2025 against the Turkish defense industry; BinDiff scored only 8.6% similarity, discounted due to control-flow flattening. No CVE is involved.

## MITRE ATT&CK

- T1566.001 Spearphishing Attachment
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1053.005 Scheduled Task
- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1620 Reflective Code Loading
- T1685 Disable or Modify Tools
- T1497.001 System Checks
- T1057 Process Discovery
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1614 System Location Discovery
- T1083 File and Directory Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1132.001 Standard Encoding
- T1573.001 Symmetric Cryptography
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [Tracking Dropping Elephant Tradecraft: China-Themed Loader Chain Delivering Memory-Resident RAT](https://www.rapid7.com/blog/post/tr-malware-tracking-dropping-elephant-tradecraft-china-themed-loader-chain)
- [Dropping Elephant APT Group Targets Turkish Defense Industry: LOLBAS, VLC Player, and Encrypted Shellcode](https://arcticwolf.com/resources/blog/dropping-elephant-apt-group-targets-turkish-defense-industry/)
- [Patchwork, Hangover Group, Dropping Elephant, MONSOON, Operation Hangover (G0040)](https://attack.mitre.org/groups/G0040/)
- [Dark Web Profile: Patchwork APT](https://socradar.io/dark-web-profile-patchwork-apt/)
- [A Deep Dive Into Patchwork APT Group](https://cyble.com/blog/a-deep-dive-into-patchwork-apt-group/)
- [MONSOON Cyber-Espionage Campaign Linked to Patchwork APT](https://www.securityweek.com/monsoon-cyber-espionage-campaign-linked-patchwork-apt/)
- [QUILTED TIGER (Threat Actor) - Malpedia](https://malpedia.caad.fkie.fraunhofer.de/actor/quilted_tiger)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0838
