SYMBOLCOMMON_NAMEaka. SYNONYMS
win.unidentified_125 (Back to overview)

Unidentified 125 (RAT, Dropping Elephant)

Actor(s): QUILTED TIGER


According to Rapid7, this RAT loaded by Donut is a native 32-bit C++ remote access implant that is mapped and executed entirely in memory by a shellcode-based loader. It features extensive obfuscation and stealth characteristics, including control-flow flattening, dynamic API resolution, static CRT linking, and multiple anti-analysis checks for debuggers, sandboxes, virtualized environments, and geolocation. The malware fingerprints the host by collecting system and user information plus a full process list, then communicates with its command-and-control over HTTPS with fields protected using Salsa20-based encryption and layered encoding. Its core capabilities include recursive directory listing, downloading and executing additional payloads, interactive shell command execution, on-demand screenshot capture, and exfiltration of arbitrary files.

References
2026-06-17Rapid7Anna Širokova
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
Unidentified 125 (RAT, Dropping Elephant)

There is no Yara-Signature yet.