{"id":58366,"date":"2026-06-23T20:07:34","date_gmt":"2026-06-24T00:07:34","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=58366"},"modified":"2026-06-23T20:07:34","modified_gmt":"2026-06-24T00:07:34","slug":"dropping-elephant-googleerrorreport-malware","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/dropping-elephant-googleerrorreport-malware\/","title":{"rendered":"Dropping Elephant Adds GoogleErrorReport Scheduled Task for Persistence"},"content":{"rendered":"<p>The <a href=\"https:\/\/overcentral.com\/en\/darkweb-threat-actor-czech-republic-data-breach\/\" title=\"DarkWeb Threat Actor Exposes Czech Republic Data Breach\" data-iacss-internal=\"1\">threat actor<\/a> known as Dropping Elephant has resurfaced with a significantly refined and more dangerous campaign, deploying a reworked remote access trojan (RAT) through a <a href=\"https:\/\/overcentral.com\/en\/tesla-fsd-fraud-lawsuit-china\/\" title=\"Tesla Faces First FSD Fraud Lawsuit Hearing in China\" data-iacss-internal=\"1\">China<\/a>aaa-themed lure document. This latest operation is engineered for stealth, evasion, and complete system compromise, marking a notable evolution in the group&#8217;s tradecraft while retaining its core operational signatures.<\/p>\n<h2>Campaign Overview: From LNK File to In-Memory RAT<\/h2>\n<p>The attack chain begins with a malicious Windows shortcut file named GRES3001.lnk, which is disguised as a PDF document related to an industrial energy contract. When a victim opens this file, it silently executes a PowerShell script that downloads additional malware components from a staging server hosted at chinagreenenergy[.]org. To maintain the illusion of legitimacy, a decoy document concerning a GRES-3 seawater pump contract is displayed to the user while the malicious activity unfolds in the background.<\/p>\n<p>Researchers from <a href=\"https:\/\/www.rapid7.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Rapid7<\/a> identified this campaign during a proactive threat hunt. Their analysis confirmed the activity as a direct evolution of Dropping Elephant\u2019s methods, noting clear overlaps in delivery patterns, screenshot logic, beaconing behavior, and command-handler structure. The researchers were able to download all attack artifacts because the staging server remained active at the time of their analysis.<\/p>\n<h2>DLL Side-Loading and Memory-Only Payload Execution<\/h2>\n<p>The downloaded files include a legitimate Microsoft binary called Fondue.exe, which is abused for DLL side-loading. This binary loads a malicious file disguised as APPWIZ.cpl. The loader then decrypts an encrypted file named editor.dat and passes the decrypted content to a Donut shellcode loader. This loader maps the final RAT directly into the system&#8217;s memory without ever writing it to disk, a technique that effectively bypasses most traditional file-based antivirus and endpoint detection solutions.<\/p>\n<p>Once active, the RAT fingerprints the victim machine and establishes a connection to a command-and-control (C2) server at gcl-power[.]org over encrypted HTTPS traffic on port 443. The malware checks in with the C2 server every 10 seconds and is capable of executing commands, listing files, capturing screenshots, uploading files, and downloading additional tools. This level of access provides the operator with full visibility and control over the infected host.<\/p>\n<h2>GoogleErrorReport Scheduled Task for Persistence<\/h2>\n<p>After staging all necessary files in the C:\\Users\\Public\\ folder, the PowerShell script creates a scheduled task named GoogleErrorReport. This task is configured to run Fondue.exe every single minute, ensuring the malware restarts automatically and remains active even if the initial process is terminated. The name GoogleErrorReport is deliberately chosen to <a href=\"https:\/\/overcentral.com\/en\/007-first-light-disguise-guide\/\" title=\"007 First Light Disguise Guide: When and How to Blend In\" data-iacss-internal=\"1\">blend in<\/a> with normal system activity and avoid raising suspicion from users or security tools.<\/p>\n<p>The script then deletes the original shortcut file, removing the most visible trace of the initial infection. From that point, the scheduled task becomes the sole persistence mechanism, repeatedly triggering the DLL side-loading chain that loads the RAT into memory. Rapid7 noted that defenders should watch for a scheduled task by this exact name running binaries from C:\\Users\\Public, as it is one of the clearest detection opportunities in this campaign.<\/p>\n<h2>Advanced Evasion and Anti-Analysis Capabilities<\/h2>\n<p>The final RAT is designed to frustrate security researchers and bypass detection tools. It employs control-flow flattening to scramble its code structure, making static analysis difficult. It also checks for processes tied to debuggers and sandboxes, resolves its API functions at runtime, and patches critical Windows security features\u2014including AMSI (Anti-Malware Scan Interface), WLDP (Windows Lockdown Policy), and ETW (Event Tracing for Windows)\u2014before executing its payload. These layers of evasion make both static and dynamic analysis significantly harder.<\/p>\n<p>Before connecting to its C2 server, the RAT quietly pings google.com, yahoo.com, and cloudflare.com to confirm internet access. It checks the host\u2019s public IP through api.ipify.org and uses ip2c.org to identify the victim\u2019s country. All communication is encrypted with the Salsa20 cipher and wrapped in Base64 encoding, making intercepted traffic very difficult to analyze.<\/p>\n<h2>What Defenders Should Focus On<\/h2>\n<p>Rapid7 recommends that defenders avoid relying solely on static indicators of compromise (IoCs), as hashes, filenames, and infrastructure are likely to shift across campaigns. Instead, security teams should focus on behavioral signals. Key detection opportunities include shortcut files spawning PowerShell, files staged in the C:\\Users\\Public\\ directory, and any scheduled task named GoogleErrorReport running binaries from outside a legitimate Windows directory.<\/p>\n<p>Endpoint tools should also be reviewed for their ability to detect memory-resident payloads and in-process tampering with security controls like AMSI and ETW. Organizations should prioritize deploying a multi-layer endpoint protection solution that includes behavioral analysis and memory scanning capabilities to defend against this type of fileless attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The threat actor known as Dropping Elephant has resurfaced with a significantly refined and more dangerous campaign, deploying a reworked remote access trojan (RAT) through a Chinaaaa-themed lure document. This latest operation is engineered for stealth, evasion, and complete system compromise, marking a notable evolution in the group&#8217;s tradecraft while retaining its core operational signatures. [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84439,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/58366.png","fifu_image_alt":"Dropping Elephant Adds GoogleErrorReport Scheduled Task for Persistence","footnotes":""},"categories":[349],"tags":[],"class_list":["post-58366","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/58366.png","fifu_image_alt":"Dropping Elephant Adds GoogleErrorReport Scheduled Task for Persistence","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/58366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=58366"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/58366\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84439"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=58366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=58366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=58366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}