VTPRACTITIONERS{SEQRITE}: Tracking UNG0002, Silent Lynx and DragonClone
ID: 872493bc-1957-5925-b455-0076419b7a76
STIX ID: report--872493bc-1957-5925-b455-0076419b7a76
Feed Name: VirusTotal Blog
This VirusTotal-hosted success story from SEQRITE describes how analysts used VT pivots to uncover and track multiple APT campaigns (UNG0002, Silent Lynx, DRAGONCLONE) active in 2024–2025 across Central, South and East Asia; techniques included Cobalt Strike beacons, DLL sideloading, custom implants (C++ and V-Shell), PowerShell blobs, and use of LNK metadata, certificates, and Telegram bot tokens as IOCs, with practical hunting tips (malware_config, YARA, Sigma, Livehunt) for threat detection and attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
