news.mlab.sh
Back to the feed
threat-intel

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

High
Summary

A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy the AdaptixC2 agent AZUREVEIL. This campaign utilizes a dead-drop C2 model leveraging Microsoft Azure Blob Storage, and is attributed to China-aligned threat actors. Simultaneously, other China-linked groups, including TencShell and variants of SteppeDriver and NegativeGlimmer, are conducting attacks globally, employing tools like rshell and Cobalt Strike to compromise systems and exfiltrate data.

The Operation Dragon Weave campaign represents a significant escalation in cyber espionage activity, specifically targeting sectors like government, research, academic, technology, and financial services. The attackers are employing a sophisticated multi-stage attack chain, beginning with spear-phishing emails containing ZIP archives. These archives contain legitimate-looking files designed to trigger a chain of malicious actions, ultimately leading to the deployment of the AdaptixC2 agent, AZUREVEIL. The use of a Rust loader and a dead-drop C2 model via Microsoft Azure Blob Storage adds a layer of obfuscation and difficulty for detection. The malware’s ability to perform a wide range of post-compromise actions, including file operations, command execution, and network pivoting, grants attackers significant control over the infected systems.

Beyond the Dragon Weave campaign, the article highlights ongoing activity by other China-aligned threat actors. Specifically, Cato Networks detected an intrusion attempt against a global manufacturing customer in India, utilizing the TencShell implant derived from the rshell C2 framework. Simultaneously, ESET’s ongoing intelligence indicates continued high activity from groups like SteppeDriver and NegativeGlimmer, each utilizing distinct toolkits and targeting diverse regions. These groups demonstrate a persistent and adaptable approach to cyber espionage, leveraging established frameworks and techniques to achieve their objectives. The diverse range of tools and tactics underscores the sophistication and breadth of China’s cyber espionage capabilities.

Read the full article at The Hacker News