logo

Operation Dragon Weave Exposed: Cyber Espionage Campaign Weaponizes Cloud Storage

ID: bf789497-e0a9-5740-9152-9a9a77d1c290

STIX ID: report--bf789497-e0a9-5740-9152-9a9a77d1c290

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Do Son

...
...

Operation Dragon Weave is a targeted international cyber-espionage campaign observed by Seqrite that uses phishing lures to deliver a multi-path infection chain (shortcut-based and a Rust dropper) which converges on RuntimeBroker_update.exe and a RUSTCLOAK loader; that loader performs triple-layer decryption and injects a memory-resident remote control agent named AZUREVEIL that uses Microsoft Azure Blob Storage as a dead-drop C2, employing advanced sandbox evasion, DLL sideloading, Windows fibers and extensive post-exploitation capabilities with apparent China-linked attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.