APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2
ID: a095118e-65be-57c5-98de-439335fe0493
STIX ID: report--a095118e-65be-57c5-98de-439335fe0493
Feed Name: The Hacker News
Cybersecurity researchers disclosed an advanced persistent threat named Silver Dragon—linked to APT41—that has conducted targeted campaigns against government and other entities in Europe and Southeast Asia since at least mid‑2024. The group uses public‑facing server exploits and phishing to gain access, then employs three primary infection chains (AppDomain hijacking, service DLL/BamboLoader, and LNK-based phishing) to deploy Cobalt Strike beacons. Post‑exploitation includes custom loaders (MonikerLoader, BamboLoader), backdoors and tools (SilverScreen, SSHcmd, GearDoor) that use Google Drive for file-based C2, with diverse plugins and file-extension conventions for tasking and exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
