The Silver Dragon, which is affiliated with the Chinese APT41, has been identified as conducting widespread cyberattacks against government entities in Europe and Southeast Asia since mid- 2024. The group uses advanced techniques such as Cobalt Strike and Google Drive for command-and-control communication, while exploiting vulnerable servers and phishing emails for initial access.
See also: Chinese hackers APT31 target Russian IT companies

According to cybersecurity researchers at Check Point Research, Silver Dragon operates under the umbrella of APT41, one of the most active Chinese advanced persistent threat groups that has been active since 2012.APT41 , and media, combining cyberespionage with financial motives.
Silver Dragon attacks begin by exploiting publicly accessible internet servers and sending phishing emails containing malicious attachments. To maintain their presence on target systems, the group hijacks legitimate Windows services , allowing malicious processes to blend in with normal system activity. This technique makes detection extremely difficult for traditional security systems.
The group uses Cobalt Strike beacons to achieve persistence on compromised hosts, while implementing techniques such as DNS tunneling for command-and-control communication to bypass detection systems. Researchers identified three different infection chains for Cobalt Strike: AppDomain hijacking, service DLL , and email phishing.
See also: Chinese APT24 distributes BADAUDIO malware

The first two infection chains, AppDomain hijacking and Service DLL, show clear operational overlap and are delivered via compressed files, indicating their use in post-exploitation scenarios. In many cases, these chains were deployed after publicly exposed vulnerable servers were compromised.
Both chains use a RAR file containing a batch script. The first chain uses the script to install MonikerLoader, a .NET-based loader that is responsible for decrypting and executing a second stage directly in memory. The second stage mimics the behavior of MonikerLoader, acting as a pipeline for loading the final Cobalt Strike beacon payload.
The DLL service uses a batch script to deliver a shellcode DLL loader called BamboLoader, which is registered as a Windows. This heavily obfuscated C++ malware is used to decrypt and decompress shellcode stored on disk and inject it into a legitimate Windows, such as “taskhost.exe“. The binary targeted for injection is configurable within BamboLoader. The Silver Dragon
The third infection chain involves a phishing campaign that has primarily targeted Uzbekistan with malicious Windows (LNK) as attachments. The weaponized LNK file is designed to launch PowerShell via “cmd.exe”, leading to the extraction and execution of next-stage payloads.
See also: Chinese 'Jewelbug' was on Russian IT provider's network for months

To protect against such threats, experts recommend immediately applying patches to publicly accessible servers, blocking phishing attachments (LNK, ZIP, RAR), monitoring Windows for hijacking, and implementing MFA on all critical services. Using advanced EDR solutions to detect loaders such as BamboLoader and network segmentation to limit lateral movement are also critical protection measures.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
