Dropping Elephant APT Group Targets Turkish Defense Industry With New Campaign and Capabilities: LOLBAS, VLC Player, and Encrypted Shellcode

July 24, 2025, 9:06 a.m.

Description

The Arctic Wolf Labs team has uncovered a new cyber-espionage campaign by the Dropping Elephant APT group targeting Turkish defense contractors. The attack leverages a five-stage execution chain delivered via malicious LNK files disguised as conference invitations. It uses legitimate binaries like VLC Media Player for defense evasion through DLL side-loading. The campaign demonstrates an evolution in the group's capabilities, transitioning from x64 DLL variants to x86 PE executables with enhanced command structures. The timing coincides with increased Turkey-Pakistan defense cooperation amid India-Pakistan tensions, suggesting geopolitical motives. The attack chain includes social engineering, PowerShell scripting, file obfuscation, and a custom remote access trojan for intelligence gathering.

Date

  • Created: July 23, 2025, 11:31 p.m.
  • Published: July 23, 2025, 11:31 p.m.
  • Modified: July 24, 2025, 9:06 a.m.

Indicators

  • 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2
  • 89ec9f19958a442e9e3dd5c96562c61229132f3acb539a6b919c15830f403553
  • 588021b5553838fae5498de40172d045b5168c8e608b8929a7309fd08abfaa93
  • 4cc729b554326ccc62205d46b95353dcb34cadf095b904e941814e902e0925b2
  • 341f27419becc456b52d6fbe2d223e8598065ac596fa8dec23cc722726a28f62
  • 2cd2a4f1fc7e4b621b29d41e42789c1365e5689b4e3e8686b80f80268e2c0d8d
  • 01a635a11a140aef906efe9db22fb66b0d6510e1e702870c4c728099fd5ab455
  • roseserve.org
  • expouav.org
  • rosereserve.org

Attack Patterns

Additional Informations

  • Defense

Linked vulnerabilities