logo

China's Silver Dragon Razes Governments in EU, SE Asia

ID: e51415fb-b15d-5d0e-a658-99ab33630151

STIX ID: report--e51415fb-b15d-5d0e-a658-99ab33630151

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Silver Dragon, a suspected APT41 spinoff active since at least mid-2024, is conducting targeted cyber-espionage against government entities in Southeast Asia and Europe. The group gains access via exploited public-facing servers and phishing (including weaponized LNK attachments), achieves persistence through Service DLL/AppDomain hijacking, and uses a mix of off-the-shelf (Cobalt Strike, DNS tunneling) and custom tools (BamboLoader, GearDoor using Google Drive C2, SSHcmd, SilverScreen) to blend into legitimate system activity; Check Point recommends patching internet-facing systems and monitoring Windows service configuration and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.