Dropping Elephant APT Group Targets Turkish Defense Industry With New Campaign and Capabilities: LOLBAS, VLC Player, and Encrypted Shellcode
July 24, 2025, 9:06 a.m.
Description
The Arctic Wolf Labs team has uncovered a new cyber-espionage campaign by the Dropping Elephant APT group targeting Turkish defense contractors. The attack leverages a five-stage execution chain delivered via malicious LNK files disguised as conference invitations. It uses legitimate binaries like VLC Media Player for defense evasion through DLL side-loading. The campaign demonstrates an evolution in the group's capabilities, transitioning from x64 DLL variants to x86 PE executables with enhanced command structures. The timing coincides with increased Turkey-Pakistan defense cooperation amid India-Pakistan tensions, suggesting geopolitical motives. The attack chain includes social engineering, PowerShell scripting, file obfuscation, and a custom remote access trojan for intelligence gathering.
Tags
Date
- Created: July 23, 2025, 11:31 p.m.
- Published: July 23, 2025, 11:31 p.m.
- Modified: July 24, 2025, 9:06 a.m.
Indicators
- 8b6acc087e403b913254dd7d99f09136dc54fa45cf3029a8566151120d34d1c2
- 89ec9f19958a442e9e3dd5c96562c61229132f3acb539a6b919c15830f403553
- 588021b5553838fae5498de40172d045b5168c8e608b8929a7309fd08abfaa93
- 4cc729b554326ccc62205d46b95353dcb34cadf095b904e941814e902e0925b2
- 341f27419becc456b52d6fbe2d223e8598065ac596fa8dec23cc722726a28f62
- 2cd2a4f1fc7e4b621b29d41e42789c1365e5689b4e3e8686b80f80268e2c0d8d
- 01a635a11a140aef906efe9db22fb66b0d6510e1e702870c4c728099fd5ab455
- roseserve.org
- expouav.org
- rosereserve.org
Additional Informations
- Defense