A newly discovered cyber espionage campaign, dubbed Operation Dragon Weave, has been targeting government officials and citizens in the Czech Republic and Taiwan, according to researchers at Seqrite Labs. The campaign primarily focuses on organizations in the government, research, academic, technology, and financial sectors. Attackers use spear-phishing emails containing ZIP file attachments that initiate a sophisticated infection chain, ultimately deploying an AdaptixC2 malware agent designed for data theft and remote control of compromised systems. The attack begins when victims extract the ZIP archive, which contains seemingly legitimate files. In one infection path, a malicious Windows Shortcut (LNK) file disguised as a PDF document triggers a PowerShell script that extracts and launches a malicious executable named RuntimeBroker_update.exe. In an alternative path, victims directly execute a Rust-based dropper included in the archive. Both methods eventually use DLL side loading to load a malicious DLL, resulting in the deployment of a Rust-based loader known as RUSTCLOAK. RUSTCLOAK decrypts and executes the final payload, an AdaptixC2 agent called AZUREVEIL, which uses Microsoft Azure Blob Storage as a command and control (C2) mechanism. Instead of communicating directly with attackers, the malware employs a dead drop approach, exchanging data through a shared Azure storage container. AZUREVEIL supports 36 commands, enabling file management, command execution, process control, port forwarding, SOCKS proxy operations, and in-memory execution of Beacon Object Files, effectively granting attackers full control over infected systems. Although no specific threat group has been formally identified, researchers believe the operation is China aligned. The disclosure comes amid reports of increased activity by China linked cyber espionage groups worldwide. Recent investigations by Cato Networks and ESET have uncovered additional malware families, including TencShell and PhiliKit, as well as campaigns targeting organizations across Europe, Asia, and Latin America, highlighting the continued global reach and sophistication of Chinese cyber threat actors.
Apache ActiveMQ users are being urged to immediately apply security updates following the disclosure of two significant vulnerabilities that could expose messaging infrastructures ...
Cybersecurity researchers have identified a previously undocumented threat cluster named OP-512, which is actively targeting internet-facing Microsoft Internet Information Services...
Security researchers have uncovered a large-scale cyber campaign in which threat actors combined exploited Fortinet weaknesses, AI-assisted tooling, and custom command-and-control ...