logo

Operation Dragon Whistle Targets Changzhou University With Malicious LNK Files

ID: dcafa2b4-c0b7-5285-8a3f-206ab9274e47

STIX ID: report--dcafa2b4-c0b7-5285-8a3f-206ab9274e47

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Varshini

...
...

A targeted phishing campaign against PSCA/PPIC3 in Pakistan used spear-phishing attachments (a macro-laden Word doc and a fake Adobe PDF) to deploy a VS Code Remote Tunnel backdoor via Microsoft device-code authentication and ClickOnce-delivered .NET payloads, exploited persistence via registry changes, and exfiltrated status codes to attacker-controlled Discord webhooks; several SHA-256 hashes are provided as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.