Sharp Dragon Expands Towards Africa and The Caribbean
ID: 843c246e-b2a3-55a9-9651-eb3bcd597a8e
STIX ID: report--843c246e-b2a3-55a9-9651-eb3bcd597a8e
Feed Name: Check Point Research
Sharp Dragon (formerly Sharp Panda), a Chinese state-linked APT, expanded targeting from Southeast Asia into Africa and the Caribbean by leveraging compromised government email accounts to distribute RoyalRoad-weaponized documents and executables that install 5.t loaders and Cobalt Strike Beacon; the report details evolving TTPs (wider recon, EXE loaders, use of public tooling), extensive IOCs (file hashes, C2 IPs/domains), and suspected exploitation of CVE-2023-0669 to repurpose compromised servers as C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
