logo

China Uses Dual-Method Cyberattack on Czech Orgs

ID: 48ccccc2-c15c-59af-850c-80ff48aaffb9

STIX ID: report--48ccccc2-c15c-59af-850c-80ff48aaffb9

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-06-02

Date Updated: 2026-06-15

Author: Alexander Culafi

...
...

Operation Dragon Weave is a China-attributed spear-phishing campaign targeting government, research/academia, technology/software, and financial organizations in the Czech Republic and Taiwan. Attackers deliver a ZIP attachment containing either an LNK that launches a PowerShell-based chain or an executable Rust dropper that ultimately runs RuntimeBroker_update.exe, which loads a Rust-based loader (Rustcloak) that decrypts and executes an Adaptix C2 agent (Azureveil). Azureveil uses Microsoft Azure Blob Storage as a dead-drop C2 for encrypted beacons, commands, and exfiltrated data; Rustcloak includes anti-analysis/sandbox-evasion checks. Seqrite recommends phishing defenses, EDR/XDR/FIM, SIEM/log centralization, process monitoring, and email filtering to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.