logo

APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2

ID: a095118e-65be-57c5-98de-439335fe0493

STIX ID: report--a095118e-65be-57c5-98de-439335fe0493

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed an advanced persistent threat named Silver Dragon—linked to APT41—that has conducted targeted campaigns against government and other entities in Europe and Southeast Asia since at least mid‑2024. The group uses public‑facing server exploits and phishing to gain access, then employs three primary infection chains (AppDomain hijacking, service DLL/BamboLoader, and LNK-based phishing) to deploy Cobalt Strike beacons. Post‑exploitation includes custom loaders (MonikerLoader, BamboLoader), backdoors and tools (SilverScreen, SSHcmd, GearDoor) that use Google Drive for file-based C2, with diverse plugins and file-extension conventions for tasking and exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.