logo

Silver Dragon APT Group Exploits Google Drive for Covert Attacks on Europe, Asia

ID: 301b6aff-0b6e-5618-a054-6f48b378d93c

STIX ID: report--301b6aff-0b6e-5618-a054-6f48b378d93c

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Silver Dragon (Chinese‑aligned APT):** This report describes a mid‑2024 onward espionage campaign targeting public sector and high‑profile organizations across Southeast Asia and parts of Europe, attributed to a group with operational overlap to APT41. Operators use phishing (weaponized LNKs), AppDomain hijacking, and service DLL sideloading to deploy Cobalt Strike and custom loaders (BamboLoader, MonikerLoader), and employ GearDoor — a .NET backdoor that uses Google Drive for file‑based C2 — alongside tools like SilverScreen and SSHcmd; the report includes multiple domain C2s and numerous file hashes as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.