From phishing to Google Drive C2: Silver Dragon expands APT41 playbook
ID: fc982c77-03c3-585d-bf42-ef108cc29a38
STIX ID: report--fc982c77-03c3-585d-bf42-ef108cc29a38
Feed Name: Security Affairs
APT group Silver Dragon (linked to APT41) has targeted high-profile government organizations in Southeast Asia and parts of Europe since mid-2024, gaining access via exploited public-facing servers and phishing with weaponized attachments. The group uses heavily obfuscated loaders (MonikerLoader, BamboLoader) to decrypt and inject payloads that ultimately deploy Cobalt Strike beacons, alongside custom tools (SilverScreen, SSHcmd, GearDoor) that include Google Drive-based command-and-control; persistence and evasion techniques include AppDomain and legitimate Windows service DLL hijacking, weaponized LNKs, and evidence of automated, tailored payload generation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
