Mysterious Elephant APT Hackers Infiltrate Organization to Steal Sensitive Information
In recent observations, an advanced persistent threat (APT) group named Mysterious Elephant has been identified targeting government and diplomatic entities in the Asia-Pacific region. This group employs sophisticated techniques, utilizing both…
In recent observations, an advanced persistent threat (APT) group named Mysterious Elephant has been identified targeting government and diplomatic entities in the Asia-Pacific region. This group employs sophisticated techniques, utilizing both custom-built malware and adapted open-source tools to evade detection and maintain persistent access.
Initially reported by Kaspersky’s Global Research and Analysis Team in 2023, Mysterious Elephant has shown significant advancements in its methods. The group initially used spear-phishing emails containing malicious Office documents exploiting CVE-2017-11882. Upon user interaction, a lightweight PowerShell loader is executed, retrieving more complex payloads from attacker-controlled servers. This loader, known as BabShell , forms the core of their modular attack framework.
As of 2025, the group has integrated an additional loader, MemLoader HidenDesk , which injects remote access trojans directly into memory, thereby reducing forensic evidence on disk.
The group employs spear-phishing emails with RTF documents that exploit a memory corruption vulnerability in the Office Equation Editor. This triggers a hidden PowerShell process to download and execute the BabShell DLL loader. BabShell then decrypts its configuration and establishes a communication channel with its command and control (C2) servers.
Initially reported by Kaspersky’s Global Research and Analysis Team in 2023, Mysterious Elephant has shown significant advancements in its methods.
Further stages involve the deployment of MemLoader HidenDesk, which injects a remote access trojan (RAT) variant into a system service process. This method of avoiding disk writes complicates detection and forensic analysis.
Subsequent phases focus on the exfiltration of sensitive data, including WhatsApp documents and images. Custom tools, Uplo Exfiltrator and Stom Exfiltrator , are utilized for this purpose. The stolen data is encoded using XOR-based obfuscation and transmitted over HTTP to specific DNS domains.
The use of legitimate domains and HTTPS complicates network-based detection, as the malicious traffic blends with regular web use.
Mysterious Elephant demonstrates a high level of technical sophistication and resourcefulness. Their evolving tactics and use of open-source codebases with custom modifications highlight the need for adaptive defense strategies to safeguard sensitive information effectively.
Based on reporting by Cyber Security News.
