logo

VTPRACTITIONERS{SEQRITE}: Tracking UNG0002, Silent Lynx and DragonClone

ID: 872493bc-1957-5925-b455-0076419b7a76

STIX ID: report--872493bc-1957-5925-b455-0076419b7a76

Feed Name: VirusTotal Blog

Threat Score
85/100

Date Published: 2025-10-21

Date Updated: 2026-05-01

Author: Joseliyo Sánchez

...
...

This VirusTotal-hosted success story from SEQRITE describes how analysts used VT pivots to uncover and track multiple APT campaigns (UNG0002, Silent Lynx, DRAGONCLONE) active in 2024–2025 across Central, South and East Asia; techniques included Cobalt Strike beacons, DLL sideloading, custom implants (C++ and V-Shell), PowerShell blobs, and use of LNK metadata, certificates, and Telegram bot tokens as IOCs, with practical hunting tips (malware_config, YARA, Sigma, Livehunt) for threat detection and attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.