Friday, September 18, 2026

Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT

A sophisticated malvertising and social-engineering campaign that pivoted from weaponized GitLab Pages to abusing claude.ai’s shared chat feature, enabling operators to deliver an in-memory remote-access trojan (RAT) via a China-themed loader chain.

Across seven weeks (April 8–June 14, 2026) investigators tracked 106 unique malicious hostnames across six attack waves, revealing rapid infrastructure rotation, targeted geographic focus, and iterative lure testing that prioritized AI developer tooling keywords.

The attack flow blended paid search malvertising, trusted-host abuse, and copy-paste “ClickFix” social engineering.

Google Ads lured technically proficient users searching for AI developer tools with ads impersonating legitimate brands Claude, ChatGPT Codex, Perplexity, Cursor IDE, JetBrains and others and directed them either to GitLab Pages subdomains or, later, to claude.ai shared-chat URLs.

Using free, high-reputation platforms (gitlab.io and claude.ai) let the actors bypass domain-based filters and browser heuristics; victims landed on valid, properly certified pages where standard URL- and certificate-based defenses offered no signal of compromise.


Infection chain of the Claude malvertising campaign (Source : TrendAI).
Infection chain of the Claude malvertising campaign (Source : TrendAI).

Early waves relied on 92 malicious GitLab Pages hostnames that mimicked software download pages and delivered ClickFix instructions prompting victims to open Terminal or PowerShell and paste a command.

According to TrendAI™ Research tracked 106 unique malicious hostnames deployed across six distinct attack waves over just seven weeks with operators continuously rotating infrastructure and testing new AI brand lures.

That command fetched and executed a multi-stage loader hosted on attacker infrastructure. The loader chain incorporated a China-themed motif in its naming and behaviors, but analysis shows the primary purpose was to stage an in-memory RAT rather than to install a persistent disk-resident payload.

China-Themed Loader Chain

The loader decrypted and executed the RAT entirely in memory, reducing forensic artifacts and complicating detection by endpoint protection solutions that rely on file-based signatures.

Top 20 countries by confirmed victim count (Source : TrendAI).
Top 20 countries by confirmed victim count (Source : TrendAI).

A significant tactical escalation occurred when operators weaponized claude.ai’s Share feature. TrendAI™ observed at least 61 unique shared conversation IDs and multiple Google Ads campaign IDs directly pointing to claude.ai/share/<uuid> URLs.

Because the malicious content resided on claude.ai itself, defenses that flag low-reputation domains or certificate anomalies were effectively neutralized.

The shared chats impersonated trusted support personas (for example, “Apple Support” or “Corda Team”) and presented curated instructions typically a single curl piped through base64 decode that ultimately fetched a loader script.


Apple Support" variant Shared by Apple Support, titled "Running Claude Code on Mac" (Source : TrendAI).
Apple Support” variant Shared by Apple Support, titled “Running Claude Code on Mac” (Source : TrendAI).

That script performed environment checks (notably excluding systems with Russian keyboard layouts) and, if cleared, retrieved and executed a MacSync infostealer variant before pivoting to the in-memory RAT stage.

The campaign’s dual-use infrastructure also hosted Mac utility scams, illustrating operator diversification to maximize clickthroughs.

Geographically the campaign disproportionately impacted the Asia-Pacific region, which accounted for roughly 67% of confirmed victims; Taiwan alone contributed about 30.5% of traffic.

The concentrated distribution signals deliberate geo-targeting in Google Ads and iterative keyword testing across AI brands to optimize engagement.


Top 10 countries affected by number of confirmed victim interactions (Source : TrendAI).
Top 10 countries affected by number of confirmed victim interactions (Source : TrendAI).

Operators continuously rotated pages and campaign parameters across weekly waves, using performance telemetry to refine lures and broaden targeting to Singapore, India, and European countries in later waves.

Upon notification, Anthropic removed the malicious shared conversations, banned the responsible accounts, and implemented additional abuse mitigations for shared chats.

TrendAI™ continues to monitor the campaign and recommends immediate defensive actions: disable risky copy-paste execution workflows, educate users on ClickFix-style prompts, implement script-blocking and shell command inspection at endpoints, monitor for in-memory RAT indicators.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains

China-aligned threat actors are using low-quality Chinese-language casino and...

Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware

Feral Wolf has expanded its ransomware tradecraft by abusing...

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

A newly observed ransomware operation dubbed SETTRA is abusing...

JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data

JADEPUFFER, the agentic threat actor first linked to an...

ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

Threat actors are increasingly impersonating OpenAI’s ChatGPT service in...

Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell

Linux administrators are being urged to patch four newly...

Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability

More than 100,000 WordPress sites using the Tutor LMS...

Related Articles

Recent News