Operation Dragon Weave Exposed: Cyber Espionage Campaign Weaponizes Cloud Storage
ID: bf789497-e0a9-5740-9152-9a9a77d1c290
STIX ID: report--bf789497-e0a9-5740-9152-9a9a77d1c290
Feed Name: securityonline.info
Operation Dragon Weave is a targeted international cyber-espionage campaign observed by Seqrite that uses phishing lures to deliver a multi-path infection chain (shortcut-based and a Rust dropper) which converges on RuntimeBroker_update.exe and a RUSTCLOAK loader; that loader performs triple-layer decryption and injects a memory-resident remote control agent named AZUREVEIL that uses Microsoft Azure Blob Storage as a dead-drop C2, employing advanced sandbox evasion, DLL sideloading, Windows fibers and extensive post-exploitation capabilities with apparent China-linked attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
