Mapping Dropping Elephant’s AKA ChinastRats AutoIT Malware Campaign Infrastructure
With a Surprising Twist: Shared Infrastructure Linked to GandCrab Ransomware Sophisticated, stealthy, and persistent. These are the hallmarks of the latest campaign attributed to the Dropping Elephant (aka Chinastrats) threat group.

With a Surprising Twist: Shared Infrastructure Linked to GandCrab Ransomware
Sophisticated, stealthy, and persistent. These are the hallmarks of the latest campaign attributed to the Dropping Elephant (aka Chinastrats) threat group. Our team recently conducted a detailed infrastructure mapping operation on their latest campaign, which utilizes malicious Microsoft Office documents embedded with AutoIT malware to target high value organizations.
But what we discovered went beyond expectations.
During our investigation, our analysts uncovered overlapping infrastructure previously linked to the GandCrab ransomware a now defunct but once notorious ransomware as a service (RaaS) operation. This finding suggests either infrastructure reuse, shared services, or deeper links between cyber espionage and cybercrime actors than previously understood.
Campaign Summary

The attack begins with targeted phishing emails containing weaponized Office documents. Once opened, these files deploy AutoIT compiled scripts to:
- Install backdoors
- Collect system and user data
- Communicate with remote servers
- Execute follow on payloads for espionage
This campaign has been active across regions of strategic interest, with signs pointing toward long term intelligence gathering as the primary objective.
Why Infrastructure Mapping Is Critical
Mapping attacker infrastructure isn’t just about blocking a few domains. It’s about revealing how attackers build, scale, and repurpose digital assets across multiple campaigns.
Key benefits of infrastructure mapping include:
1.Early detection of campaign staging activity
2.Correlation between unrelated malware families (like espionage and ransomware)
3.Identification of fallback or backup C2 channels
4.Strengthened detection logic across SOC tools and SIEM platforms
Your security posture improves drastically when you can see the whole battlefield not just the first move.
Shared Infrastructure with GandCrab Ransomware
One of the most significant discoveries during this research was that some of the command and control (C2) infrastructure used in the Dropping Elephant campaign had historical ties to GandCrab ransomware operations.
This raises several possibilities:
The infrastructure is being sold or leased on dark web forums
Actors are repurposing abandoned GandCrab servers
There may be direct collaboration or a shared operational platform
Either way, this overlap increases the risk level and highlights the importance of ongoing infrastructure correlation and monitoring.
IOCs to Block Immediately
| Type | Indicator |
|---|---|
| Domain | strategicwebportals[.]com |
| Domain | filesynccloud[.]online |
| Domain | documentcloudpro[.]info |
| Domain | netsyncsafeguard[.]com |
| Domain | office365-update[.]live |
| URL | http://filesynccloud[.]online/download.exe |
| URL | http://documentcloudpro[.]info/update.doc |
| URL | http://strategicwebportals[.]com/info.vbs |
| URL | http://netsyncsafeguard[.]com/office.bat |
What This Means for You
This campaign showcases how nation state threat actors are increasingly leveraging or intersecting with cybercriminal infrastructure. If you’re only defending against one category of threat, you’re leaving yourself exposed.
If you:
1.Use Microsoft Office tools daily
2.Manage sensitive data or communications
3.Operate in government, defense, legal, or corporate strategy sectors
…then you’re a prime target.
How Alpha Cyber Can Help
At Alpha Cyber, we specialize in infrastructure mapping, threat actor profiling, and advanced threat hunting. Our team connects the dots between malware families, attacker tactics, and infrastructure patterns to provide actionable intelligence before threats become breaches.
We provide:
1.Continuous IOC and infrastructure monitoring
2.Realtime threat correlation
3.Custom threat intelligence feeds
4.Rapid incident response support
Take Action Now
The overlap between Dropping Elephant and GandCrab infrastructure is a red flag that threat actor ecosystems are more connected than ever.
Let our team run a threat scan across your environment to check for exposure.



