Friday, September 11, 2026

Silver Dragon APT Group Exploits Google Drive for Covert Attacks on Europe, Asia

Silver Dragon is a Chinese‑aligned APT group that has been targeting public sector and high‑profile organizations in Europe and Southeast Asia since at least mid‑2024, with strong operational overlap to APT41 tradecraft.

The group combines classic post‑exploitation tooling like Cobalt Strike with new custom malware that abuses Google Drive as a covert command‑and‑control (C2) channel.research.

Silver Dragon focuses on government ministries and public sector entities, primarily in Southeast Asia but also across parts of Europe, indicating a clear cyber‑espionage motive.

Analysts assess the actor as operating under the broader APT41 umbrella based on script similarity, overlap in Cobalt Strike configurations, and consistent UTC+8 compilation patterns.

The group relies on two main initial access vectors: exploitation of public‑facing internet servers and email‑based phishing that delivers malicious attachments, including weaponized LNK files.

Check Point Research (CPR) has been tracking a sophisticated Chinese-aligned threat group whose activity demonstrates operational correlation with campaigns previously associated with APT41.

Once a foothold is established, operators deploy Cobalt Strike beacons and often tunnel C2 traffic over DNS to evade perimeter monitoring and traditional HTTP‑centric detections.research.

Silver Dragon APT Group

CPR documented three primary infection chains: AppDomain hijacking, a Service DLL chain, and a phishing‑driven LNK chain, all converging on Cobalt Strike as the final payload.

BamboLoader In-memory payload decryption followed by process injection (Source : Check Point Research).
 BamboLoader In-memory payload decryption followed by process injection (Source : Check Point Research).

The AppDomain hijacking path abuses .NET configuration files (for binaries such as dfsvc.exe and tzsync.exe) to redirect execution into a malicious loader dubbed MonikerLoader, which decrypts and executes staged shellcode purely in memory.

The Service DLL chain is more minimal and centers on BamboLoader, a heavily obfuscated x64 C++ loader registered as a Windows service by hijacking legitimate service names like Windows Update or Bluetooth services execution.

Install scripts stop and delete the original service, copy the malicious DLL into system paths, then recreate the service pointing to the attacker’s loader, a pattern previously documented in APT41 operations.

High-level overview of the AppDomain hijacking infection chain (Source : Check Point Research).
High-level overview of the AppDomain hijacking infection chain (Source : Check Point Research).

In the phishing chain, oversized LNK attachments embed PowerShell that extracts multiple payloads from the shortcut itself, drops a decoy PDF, and abuses a legitimate executable (GameHook.exe) for DLL sideloading of BamboLoader.

Across all chains, Cobalt Strike beacons use hybrid HTTP/DNS profiles, cracked watermarks, and, in some cases, SMB‑based lateral C2 inside victim networks.

GearDoor: Google Drive–based C2

The standout capability in Silver Dragon’s toolkit is GearDoor, a .NET backdoor that uses Google Drive as its primary C2 channel, effectively hiding malicious traffic inside a trusted cloud platform.

GearDoor employs Brainfuck‑style string obfuscation and DES encryption, deriving its keys from MD5‑based material and assigning each host a unique identifier that maps directly to a dedicated folder on Google Drive.

All tasking is file‑based: specific extensions (such as .png, .cab, .7z, .pdf, .rar, .db, .bak) signal heartbeat, command execution, plugin loading, file management, payload delivery, and status reporting, with files deleted after processing to reduce forensic artifacts.

This design allows operators to run full interactive command sets (whoami, ipconfig, ps, directory operations, token theft, and command execution) while blending into normal cloud usage patterns and bypassing simple domain‑ or IP‑based blocking.

SilverScreen main loop operation (Source : Check Point Research).
 SilverScreen main loop operation (Source : Check Point Research).

Silver Dragon also operates SilverScreen, a .NET screen‑monitoring implant that captures multi‑monitor screenshots only when meaningful visual changes are detected, compressing them with JPEG plus GZIP to minimize noise and storage.

The tool impersonates active user sessions via token manipulation, enabling low‑profile surveillance inside government environments for extended periods.

Geographic distribution of targeted organizations (Source : Check Point Research).
Geographic distribution of targeted organizations (Source : Check Point Research).

Complementing this, SSHcmd is a .NET command‑line SSH wrapper built on the Renci.SshNet library, supporting direct command execution, interactive TTY, and file uploads/downloads with optional Base64‑encoded commands to evade basic logging.

Together, SilverScreen, SSHcmd, GearDoor, and the group’s custom loaders give Silver Dragon a versatile post‑exploitation toolkit that supports long‑term espionage across on‑prem and cloud‑integrated networks.

IOCs

TypeIoC
C2 Domainzhydromet[.]com
C2 Domainampolice[.]org
C2 Domainonedriveconsole[.]com
C2 Domaincopilot-cloud[.]net
C2 Domaindrivefrontend.pa-clients.workers[.]dev
C2 Domainrevitpourtous[.]com
C2 Domainwikipedla[.]blog
C2 Domainprotacik[.]com
C2 Domainoicm[.]org
C2 Domainmindssurpass[.]com
C2 Domainexchange4study[.]com
C2 Domainsplunkds[.]com
C2 Domainbigflx[.]net
GearDoor4f93be0c46a53701b1777ab8df874c837df3d8256e026f138d60fc2932e569a8
GearDoor7f89a4d5af47bc00a9ad58f0bcbe8a7be2662953dcd03f0e881cc5cbf6b7bca8
SSHcmdbcbe2f0a8134c0e7fce18d0394ababc1d910e6f7b77b8c07643434cd14f4c5d6
SilverScreen44e769efed3e4f9f04c52dcd13f15cead251a1a08827a2cb6ea68427522c7fbb
SilverScreen85a03d2e74ae84093a74699057693d11e5c61f85b62e741778cbc5fc9f89022f
Phishing LNK51684a0e356513486489986f5832c948107ff687c8501d64846cdc4307429413
Phishing LNK166e777cb72a7c4e126f8ed97e0a82e7ca9e87df7793fea811daf34e1e7e47a6
Phishing LNK948468aba5c851952ebe56a5bf37904ed83a6c8cb520304db6938d79892f0a1b
BamboLoadere3b016f2fc865d0f53f635f740eb0203626517425ed9a2908058f96a3bcf470d
BamboLoader967b5c611d304385807ea2d865fa561c15cde0473dd63e768679a4f29f0e4563
BamboLoader43f8f94ca5aa0af7bfb0cc1d2f664a46500a161b2d082b48b516d084ef485348
BamboLoader3128bdb8efaaa04c0ba96337252f4cc2dc795021cbc410f74ace9dde958bac1d
BamboLoaderb93560c4d18120e113fb8b04a8aa05f66a12116d1fbf18a93186f6314381e97e
BamboLoaderddaca57f3d5f4986da052ca172631b351410d6f5831f6af351699c6201cc011b
BamboLoaderc4de1f1a8cb3b0392802ee56096ddb25b6f51c51350ce7c45e14d8c285765300
BamboLoader7384462d420bdc9683a4cac2a8ad19353a2aa7d2244c91e9182345777e811e33
BamboLoader74a11a07d167f8f5c0baa724d1f7708985c81d0ac3d0e4d7ef3f3220c335e009
MonikerLoader5ad857df8976523cb3ad2fdf30e87c0e7daa64135716b139ffdcd209b98e1654
MonikerLoader740a09fcdefa5a5f79355b720f54ff09efa64062229fb388adbccd9c829e9ff0
MonikerLoader5341c7256542405abdd01ee288b08e49dcb6d1782be6b7bea63b459d80f9a8f5
MonikerLoader3a2df7a2cfeca5ba315a29cf313268a53a22316c925e6b9760ead8f4df0d1f75
MonikerLoader stage 22f787c1454891b242ab221b8b8b420373c3eb1a0c1fdcb624dd800c50758bbb0
MonikerLoader stage 2568c67564d62b09d1a1bc29a494cf4bf31afddcafcf78592b178c63f23ccfcae
MonikerLoader stage 219139a525ee9c22efd6a4842c4cd50ab2c5f9ee391e5531071df0bb4e685f55d
MonikerLoader stage 272e4b6540e32b8b7aac850055609bc5afc19e29834e9aa6be29a8ea59a2c9785
Install bat16b9a7358be88632378ba20ba1430786f3b844694b1f876211ecdbecf5cccbc2
Install bat37b485ed8d150d022c41e5e307b8c54c34ef806625b44d0c940b18be7d5b29ce
Install bat3e2a0bafbd44e24b17fd7b17c9f2b2a3727349971d42612d55bbc1732082619a
Install bat8c29f9189a9ad75a959024f59e68c62d42a6fd42f9eacf847128c7efe4ef7578
Install batbd699ed720e2bd7085b3444cb8f4d36870b5b48df1055ec6cc1553db3eef7faf
Install bata6b5448ba45f3f352f5f4c5376024891adda1ef8ebf62a8fe63424fa230c691d

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News