news.mlab.sh
Back to the feed
threat-intel

China Uses Dual-Method Cyberattack on Czech Orgs

High
Summary

This article details a dual-method cyberattack targeting organizations in the Czech Republic and Taiwan, orchestrated by Chinese nation-state threat actors. The campaign, dubbed "Operation Dragon Weave," utilizes a spear-phishing technique involving a zip file containing a malicious LNK shortcut and a Rust-based dropper, ultimately deploying the Azureveil C2 agent. The attack leverages Microsoft Azure Blob Storage for command and control, employing a dead-drop approach to evade detection and facilitate data exfiltration, with a focus on government, research, and financial sectors.

Chinese nation-state threat actors are conducting a sophisticated cyberattack against organizations in the Czech Republic and Taiwan, as outlined in a recent report by Seqrite. The operation, termed "Operation Dragon Weave," employs a double-layer spear-phishing campaign. Initially, victims receive emails containing a zip file, often disguised as business meeting invitations or appointments (such as with the Czech Social Security Administration), which contains an LNK shortcut file. Clicking this shortcut triggers a PowerShell script that decrypts and executes components, including the Rust-based dropper, Rustcloak.

Alternatively, victims can open the initial executable, which acts as a self-contained Rust-based dropper, extracting and launching the same RuntimeBroker_update.exe. This ultimately deploys the Azureveil malware, a command-and-control (C2) agent utilizing Microsoft Azure Blob Storage. Azureveil employs a dead-drop approach, exchanging data through a shared Azure storage container, avoiding direct communication and enhancing its ability to evade detection. The malware periodically uploads encrypted beacons to signal its activity and retrieves commands from the container to execute and exfiltrate data.

The targeting of the Czech Republic is attributed to its close ties to Taiwan and the broader intelligence-collection priorities of China-aligned APTs. The attack highlights the evolving tactics employed by state-sponsored actors, combining traditional spear-phishing with advanced malware and utilizing cloud-based infrastructure for command and control. This approach underscores the need for organizations to implement robust security measures, including multi-factor authentication, endpoint detection and response (EDR) solutions, and thorough employee training to mitigate the risk of such attacks.

Read the full article at Dark Reading