Alpha Cyber

Mapping Dropping Elephant’s AKA ChinastRats AutoIT Malware Campaign Infrastructure

With a Surprising Twist: Shared Infrastructure Linked to GandCrab Ransomware Sophisticated, stealthy, and persistent. These are the hallmarks of the latest campaign attributed to the Dropping Elephant (aka Chinastrats) threat group.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Dropping Elephant APT Army PIC

With a Surprising Twist: Shared Infrastructure Linked to GandCrab Ransomware

Sophisticated, stealthy, and persistent. These are the hallmarks of the latest campaign attributed to the Dropping Elephant (aka Chinastrats) threat group. Our team recently conducted a detailed infrastructure mapping operation on their latest campaign, which utilizes malicious Microsoft Office documents embedded with AutoIT malware to target high value organizations.

But what we discovered went beyond expectations.

During our investigation, our analysts uncovered overlapping infrastructure previously linked to the GandCrab ransomware a now defunct but once notorious ransomware as a service (RaaS) operation. This finding suggests either infrastructure reuse, shared services, or deeper links between cyber espionage and cybercrime actors than previously understood.

Campaign Summary

Dropping Elephant Graph Sharing Infra with GandCrab Ransomware

The attack begins with targeted phishing emails containing weaponized Office documents. Once opened, these files deploy AutoIT compiled scripts to:

  • Install backdoors
  • Collect system and user data
  • Communicate with remote servers
  • Execute follow on payloads for espionage

This campaign has been active across regions of strategic interest, with signs pointing toward long term intelligence gathering as the primary objective.

Why Infrastructure Mapping Is Critical

Mapping attacker infrastructure isn’t just about blocking a few domains. It’s about revealing how attackers build, scale, and repurpose digital assets across multiple campaigns.

Key benefits of infrastructure mapping include:

   1.Early detection of campaign staging activity
   2.Correlation between unrelated malware families (like espionage and ransomware)
   3.Identification of fallback or backup C2 channels
   4.Strengthened detection logic across SOC tools and SIEM platforms

Your security posture improves drastically when you can see the whole battlefield not just the first move.

Shared Infrastructure with GandCrab Ransomware

One of the most significant discoveries during this research was that some of the command and control (C2) infrastructure used in the Dropping Elephant campaign had historical ties to GandCrab ransomware operations.

This raises several possibilities:

The infrastructure is being sold or leased on dark web forums
Actors are repurposing abandoned GandCrab servers
There may be direct collaboration or a shared operational platform

Either way, this overlap increases the risk level and highlights the importance of ongoing infrastructure correlation and monitoring.

IOCs to Block Immediately

TypeIndicator
Domainstrategicwebportals[.]com
Domainfilesynccloud[.]online
Domaindocumentcloudpro[.]info
Domainnetsyncsafeguard[.]com
Domainoffice365-update[.]live
URLhttp://filesynccloud[.]online/download.exe
URLhttp://documentcloudpro[.]info/update.doc
URLhttp://strategicwebportals[.]com/info.vbs
URLhttp://netsyncsafeguard[.]com/office.bat

What This Means for You

This campaign showcases how nation state threat actors are increasingly leveraging or intersecting with cybercriminal infrastructure. If you’re only defending against one category of threat, you’re leaving yourself exposed.

If you:

   1.Use Microsoft Office tools daily
   2.Manage sensitive data or communications
   3.Operate in government, defense, legal, or corporate strategy sectors

…then you’re a prime target.

How Alpha Cyber Can Help

At Alpha Cyber, we specialize in infrastructure mapping, threat actor profiling, and advanced threat hunting. Our team connects the dots between malware families, attacker tactics, and infrastructure patterns to provide actionable intelligence before threats become breaches.

We provide:

   1.Continuous IOC and infrastructure monitoring
   2.Realtime threat correlation
   3.Custom threat intelligence feeds
   4.Rapid incident response support

Take Action Now

The overlap between Dropping Elephant and GandCrab infrastructure is a red flag that threat actor ecosystems are more connected than ever.

Let our team run a threat scan across your environment to check for exposure.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]