logo

Hackers Hide Malware Payloads Inside Nested macOS-Like Folders to Evade Scanning

ID: 46b56d06-bb43-51ec-8f31-dff10ba3b8e8

STIX ID: report--46b56d06-bb43-51ec-8f31-dff10ba3b8e8

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

Operation Dragon Whistle is a targeted spear‑phishing campaign against Chinese universities that uses ZIP attachments with nested macOS‑like folder structures to hide LNK files; those LNKs execute a VBScript that opens a decoy PDF while launching Bandizip.exe which side‑loads a malicious ark_x86.dll, ultimately deploying an in‑memory Cobalt Strike beacon with anti‑analysis checks. Seqrite links the activity to a tracked actor (UNG0002 / related campaigns), documents IoCs (file names and hashes, filenames like Bandizip.exe, ark_x86.dll, chromedo.vbs, an email.eml), and notes C2 infrastructure hosted in an Alibaba ASN, recommending deeper archive inspection, email filtering for LNKs, and endpoint monitoring for DLL side‑loading and in‑memory beacon behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.