logo

Sharp Dragon Expands Towards Africa and The Caribbean

ID: 843c246e-b2a3-55a9-9651-eb3bcd597a8e

STIX ID: report--843c246e-b2a3-55a9-9651-eb3bcd597a8e

Feed Name: Check Point Research

Threat Score
88/100

Date Published: 2024-05-23

Date Updated: 2026-04-27

Author: etal

...
...

Sharp Dragon (formerly Sharp Panda), a Chinese state-linked APT, expanded targeting from Southeast Asia into Africa and the Caribbean by leveraging compromised government email accounts to distribute RoyalRoad-weaponized documents and executables that install 5.t loaders and Cobalt Strike Beacon; the report details evolving TTPs (wider recon, EXE loaders, use of public tooling), extensive IOCs (file hashes, C2 IPs/domains), and suspected exploitation of CVE-2023-0669 to repurpose compromised servers as C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.