# Dropping Elephant Malware Campaign - China-Themed Loader Chain for Initial Access and Payload Delivery

> Dropping Elephant is an active malware campaign demonstrating sophisticated tradecraft in loader chain construction and multi-stage infection sequences. The campaign leverages China-themed decoys and social engineering to achieve initial access, followed by evasive loader stages that deliver secondary payloads for command and control.

- **Published:** 2026-06-28T00:00:00Z
- **Last reviewed:** 2026-06-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0989
- **ID:** TL-2026-0989
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** QUILTED TIGER (India)
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Dropping Elephant represents a sophisticated malware campaign characterized by a multi-stage loader chain architecture designed to evade detection and establish persistent command and control. The campaign demonstrates advanced tradecraft in payload delivery, leveraging social engineering and cultural themes (China-themed decoys) to achieve initial access. The loader chain employs multiple evasion techniques including DLL sideloading, process injection, registry persistence mechanisms, and multi-stage payload delivery. The campaign targets high-value organizations across government, financial, and technology sectors. Analysis reveals the use of legitimate tools for post-exploitation (living-off-the-land techniques), custom C2 infrastructure, and sophisticated anti-forensic capabilities. The malware family exhibits characteristics consistent with state-sponsored or well-resourced threat actors operating with advanced operational security protocols.

## MITRE ATT&CK

- T1566 Phishing
- T1195 Supply Chain Compromise
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1047 Windows Management Instrumentation
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job
- T1546 Event Triggered Execution
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1574 Hijack Execution Flow
- T1055 Process Injection
- T1036 Masquerading
- T1070 Indicator Removal
- T1633 Virtualization/Sandbox Evasion
- T1056 Input Capture
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1482 Domain Trust Discovery
- T1087 Account Discovery
- T1021 Remote Services
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1113 Screen Capture
- T1056 Input Capture
- T1071 Application Layer Protocol
- T1572 Protocol Tunneling
- T1571 Non-Standard Port
- T1041 Exfiltration Over C2 Channel
- T1048 Exfiltration Over Alternative Protocol
- T1561 Disk Wipe

## Sources

- [Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain](https://malpedia.caad.fkie.fraunhofer.de/library/e45ffac3-ec1f-4588-99f6-a936132f6b63/)
- [MITRE ATT&CK Framework - DLL Sideloading Techniques](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK Framework - Process Injection Techniques](https://attack.mitre.org/techniques/T1055/)
- [Threat Intelligence on Multi-Stage Loader Chains and Evasion Techniques](https://attack.mitre.org/techniques/T1027/)
- [Command and Control Infrastructure Analysis - C2 Beaconing Patterns](https://attack.mitre.org/techniques/T1071/)
- [Registry Run Key Persistence - Malware Persistence Mechanisms](https://attack.mitre.org/techniques/T1547/001/)
- [Scheduled Task Abuse for Persistence and Privilege Escalation](https://attack.mitre.org/techniques/T1053/005/)
- [Windows Management Instrumentation Event Subscription Persistence](https://attack.mitre.org/techniques/T1546/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0989
