logo

New Operation Dragon Whistle Phishing Campaign Targets Universities

ID: 2d95cbb3-4a63-5ba7-97b0-40dd276187ff

STIX ID: report--2d95cbb3-4a63-5ba7-97b0-40dd276187ff

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Ddos

...
...

Operation Dragon Whistle is a sophisticated, targeted phishing campaign against Chinese academic institutions that uses weaponized archives and living-off-the-land techniques. Emails deliver a double-extension LNK leading to a VBScript that shows a decoy PDF while launching a malicious chain that side-loads a trojanized DLL into a legitimate Bandizip binary, performs anti-analysis checks, disables Windows security telemetry (AMSI/ETW), and drops an in-memory Cobalt Strike beacon contacting infrastructure resolving to lysander.asia; the activity is attributed to UNG0002.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.