logo

Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2

ID: 48121467-d012-525a-a0cf-c46c1fbaab38

STIX ID: report--48121467-d012-525a-a0cf-c46c1fbaab38

Feed Name: Seqrite Blog

Threat Score
85/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Priya Patel

...
...

**Executive Summary:** Operation Dragon Weave is a targeted espionage campaign described by SEQRITE that uses spearphishing ZIP attachments and region-specific lure documents to deploy a multi-stage infection chain (LNK/VBS/PowerShell or a Rust dropper) which ultimately sideloads a malicious UnityPlayer.dll (RUSTCLOAK) to decrypt and run an Adaptix C2 agent (AZUREVEIL) entirely in memory; the agent uses Azure Blob Storage as a dead-drop C2, supports 36 post-exploitation commands including in-memory BOF execution, and includes multiple robust evasive techniques and developer artifacts—SEQRITE provides IOCs, MITRE mapping, and assesses moderate-confidence linkage to a China-based actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.