Hackers Hide Malware Payloads Inside Nested macOS-Like Folders to Evade Scanning
ID: 46b56d06-bb43-51ec-8f31-dff10ba3b8e8
STIX ID: report--46b56d06-bb43-51ec-8f31-dff10ba3b8e8
Feed Name: cybersecurityNews.com
Operation Dragon Whistle is a targeted spear‑phishing campaign against Chinese universities that uses ZIP attachments with nested macOS‑like folder structures to hide LNK files; those LNKs execute a VBScript that opens a decoy PDF while launching Bandizip.exe which side‑loads a malicious ark_x86.dll, ultimately deploying an in‑memory Cobalt Strike beacon with anti‑analysis checks. Seqrite links the activity to a tracked actor (UNG0002 / related campaigns), documents IoCs (file names and hashes, filenames like Bandizip.exe, ark_x86.dll, chromedo.vbs, an email.eml), and notes C2 infrastructure hosted in an Alibaba ASN, recommending deeper archive inspection, email filtering for LNKs, and endpoint monitoring for DLL side‑loading and in‑memory beacon behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
