216.73.217.22

Silver Dragon Targets Organizations in Southeast Asia and Europe

· Published 03/03/2026 20:03 · Modified 04/03/2026 11:17

Export JSON

Essential information

Published
03/03/2026 20:03
Modified
04/03/2026 11:17
Tags
2026-03-03 apt chinese cobalt strike dns tunneling geardoor government silverscreen southeast asia sshcmd
Related entities
31 observables, 1 intrusion sets (apt), 20 techniques (mitre), 4 malware, 16 others

Description

Check Point Research has identified a -nexus advanced persistent threat group named Silver Dragon, targeting organizations in and Europe since mid-2024. The group, likely operating under APT41, exploits public-facing servers and uses phishing emails for initial access. They deploy custom tools including , a backdoor using Google Drive for command and control, for remote access, and for covert screen monitoring. Silver Dragon primarily focuses on entities, utilizing beacons and for communication. The group's sophisticated tactics and evolving toolkit demonstrate a well-resourced and adaptable threat actor.

External references