Silver Dragon APT Group Exploits Google Drive for Covert Attacks on Europe, Asia
ID: 301b6aff-0b6e-5618-a054-6f48b378d93c
STIX ID: report--301b6aff-0b6e-5618-a054-6f48b378d93c
Feed Name: GBHackers
**Silver Dragon (Chinese‑aligned APT):** This report describes a mid‑2024 onward espionage campaign targeting public sector and high‑profile organizations across Southeast Asia and parts of Europe, attributed to a group with operational overlap to APT41. Operators use phishing (weaponized LNKs), AppDomain hijacking, and service DLL sideloading to deploy Cobalt Strike and custom loaders (BamboLoader, MonikerLoader), and employ GearDoor — a .NET backdoor that uses Google Drive for file‑based C2 — alongside tools like SilverScreen and SSHcmd; the report includes multiple domain C2s and numerous file hashes as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
