China's Silver Dragon Razes Governments in EU, SE Asia
ID: e51415fb-b15d-5d0e-a658-99ab33630151
STIX ID: report--e51415fb-b15d-5d0e-a658-99ab33630151
Feed Name: Dark Reading
Silver Dragon, a suspected APT41 spinoff active since at least mid-2024, is conducting targeted cyber-espionage against government entities in Southeast Asia and Europe. The group gains access via exploited public-facing servers and phishing (including weaponized LNK attachments), achieves persistence through Service DLL/AppDomain hijacking, and uses a mix of off-the-shelf (Cobalt Strike, DNS tunneling) and custom tools (BamboLoader, GearDoor using Google Drive C2, SSHcmd, SilverScreen) to blend into legitimate system activity; Check Point recommends patching internet-facing systems and monitoring Windows service configuration and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
