Silver Dragon is a Chinese‑aligned APT group that has been targeting public sector and high‑profile organizations in Europe and Southeast Asia since at least mid‑2024, with strong operational overlap to APT41 tradecraft.
The group combines classic post‑exploitation tooling like Cobalt Strike with new custom malware that abuses Google Drive as a covert command‑and‑control (C2) channel.research.
Silver Dragon focuses on government ministries and public sector entities, primarily in Southeast Asia but also across parts of Europe, indicating a clear cyber‑espionage motive.
Analysts assess the actor as operating under the broader APT41 umbrella based on script similarity, overlap in Cobalt Strike configurations, and consistent UTC+8 compilation patterns.
The group relies on two main initial access vectors: exploitation of public‑facing internet servers and email‑based phishing that delivers malicious attachments, including weaponized LNK files.
Check Point Research (CPR) has been tracking a sophisticated Chinese-aligned threat group whose activity demonstrates operational correlation with campaigns previously associated with APT41.
Once a foothold is established, operators deploy Cobalt Strike beacons and often tunnel C2 traffic over DNS to evade perimeter monitoring and traditional HTTP‑centric detections.research.
Silver Dragon APT Group
CPR documented three primary infection chains: AppDomain hijacking, a Service DLL chain, and a phishing‑driven LNK chain, all converging on Cobalt Strike as the final payload.

The AppDomain hijacking path abuses .NET configuration files (for binaries such as dfsvc.exe and tzsync.exe) to redirect execution into a malicious loader dubbed MonikerLoader, which decrypts and executes staged shellcode purely in memory.
The Service DLL chain is more minimal and centers on BamboLoader, a heavily obfuscated x64 C++ loader registered as a Windows service by hijacking legitimate service names like Windows Update or Bluetooth services execution.
Install scripts stop and delete the original service, copy the malicious DLL into system paths, then recreate the service pointing to the attacker’s loader, a pattern previously documented in APT41 operations.

In the phishing chain, oversized LNK attachments embed PowerShell that extracts multiple payloads from the shortcut itself, drops a decoy PDF, and abuses a legitimate executable (GameHook.exe) for DLL sideloading of BamboLoader.
Across all chains, Cobalt Strike beacons use hybrid HTTP/DNS profiles, cracked watermarks, and, in some cases, SMB‑based lateral C2 inside victim networks.
GearDoor: Google Drive–based C2
The standout capability in Silver Dragon’s toolkit is GearDoor, a .NET backdoor that uses Google Drive as its primary C2 channel, effectively hiding malicious traffic inside a trusted cloud platform.
GearDoor employs Brainfuck‑style string obfuscation and DES encryption, deriving its keys from MD5‑based material and assigning each host a unique identifier that maps directly to a dedicated folder on Google Drive.
All tasking is file‑based: specific extensions (such as .png, .cab, .7z, .pdf, .rar, .db, .bak) signal heartbeat, command execution, plugin loading, file management, payload delivery, and status reporting, with files deleted after processing to reduce forensic artifacts.
This design allows operators to run full interactive command sets (whoami, ipconfig, ps, directory operations, token theft, and command execution) while blending into normal cloud usage patterns and bypassing simple domain‑ or IP‑based blocking.

Silver Dragon also operates SilverScreen, a .NET screen‑monitoring implant that captures multi‑monitor screenshots only when meaningful visual changes are detected, compressing them with JPEG plus GZIP to minimize noise and storage.
The tool impersonates active user sessions via token manipulation, enabling low‑profile surveillance inside government environments for extended periods.

Complementing this, SSHcmd is a .NET command‑line SSH wrapper built on the Renci.SshNet library, supporting direct command execution, interactive TTY, and file uploads/downloads with optional Base64‑encoded commands to evade basic logging.
Together, SilverScreen, SSHcmd, GearDoor, and the group’s custom loaders give Silver Dragon a versatile post‑exploitation toolkit that supports long‑term espionage across on‑prem and cloud‑integrated networks.
IOCs
| Type | IoC |
|---|---|
| C2 Domain | zhydromet[.]com |
| C2 Domain | ampolice[.]org |
| C2 Domain | onedriveconsole[.]com |
| C2 Domain | copilot-cloud[.]net |
| C2 Domain | drivefrontend.pa-clients.workers[.]dev |
| C2 Domain | revitpourtous[.]com |
| C2 Domain | wikipedla[.]blog |
| C2 Domain | protacik[.]com |
| C2 Domain | oicm[.]org |
| C2 Domain | mindssurpass[.]com |
| C2 Domain | exchange4study[.]com |
| C2 Domain | splunkds[.]com |
| C2 Domain | bigflx[.]net |
| GearDoor | 4f93be0c46a53701b1777ab8df874c837df3d8256e026f138d60fc2932e569a8 |
| GearDoor | 7f89a4d5af47bc00a9ad58f0bcbe8a7be2662953dcd03f0e881cc5cbf6b7bca8 |
| SSHcmd | bcbe2f0a8134c0e7fce18d0394ababc1d910e6f7b77b8c07643434cd14f4c5d6 |
| SilverScreen | 44e769efed3e4f9f04c52dcd13f15cead251a1a08827a2cb6ea68427522c7fbb |
| SilverScreen | 85a03d2e74ae84093a74699057693d11e5c61f85b62e741778cbc5fc9f89022f |
| Phishing LNK | 51684a0e356513486489986f5832c948107ff687c8501d64846cdc4307429413 |
| Phishing LNK | 166e777cb72a7c4e126f8ed97e0a82e7ca9e87df7793fea811daf34e1e7e47a6 |
| Phishing LNK | 948468aba5c851952ebe56a5bf37904ed83a6c8cb520304db6938d79892f0a1b |
| BamboLoader | e3b016f2fc865d0f53f635f740eb0203626517425ed9a2908058f96a3bcf470d |
| BamboLoader | 967b5c611d304385807ea2d865fa561c15cde0473dd63e768679a4f29f0e4563 |
| BamboLoader | 43f8f94ca5aa0af7bfb0cc1d2f664a46500a161b2d082b48b516d084ef485348 |
| BamboLoader | 3128bdb8efaaa04c0ba96337252f4cc2dc795021cbc410f74ace9dde958bac1d |
| BamboLoader | b93560c4d18120e113fb8b04a8aa05f66a12116d1fbf18a93186f6314381e97e |
| BamboLoader | ddaca57f3d5f4986da052ca172631b351410d6f5831f6af351699c6201cc011b |
| BamboLoader | c4de1f1a8cb3b0392802ee56096ddb25b6f51c51350ce7c45e14d8c285765300 |
| BamboLoader | 7384462d420bdc9683a4cac2a8ad19353a2aa7d2244c91e9182345777e811e33 |
| BamboLoader | 74a11a07d167f8f5c0baa724d1f7708985c81d0ac3d0e4d7ef3f3220c335e009 |
| MonikerLoader | 5ad857df8976523cb3ad2fdf30e87c0e7daa64135716b139ffdcd209b98e1654 |
| MonikerLoader | 740a09fcdefa5a5f79355b720f54ff09efa64062229fb388adbccd9c829e9ff0 |
| MonikerLoader | 5341c7256542405abdd01ee288b08e49dcb6d1782be6b7bea63b459d80f9a8f5 |
| MonikerLoader | 3a2df7a2cfeca5ba315a29cf313268a53a22316c925e6b9760ead8f4df0d1f75 |
| MonikerLoader stage 2 | 2f787c1454891b242ab221b8b8b420373c3eb1a0c1fdcb624dd800c50758bbb0 |
| MonikerLoader stage 2 | 568c67564d62b09d1a1bc29a494cf4bf31afddcafcf78592b178c63f23ccfcae |
| MonikerLoader stage 2 | 19139a525ee9c22efd6a4842c4cd50ab2c5f9ee391e5531071df0bb4e685f55d |
| MonikerLoader stage 2 | 72e4b6540e32b8b7aac850055609bc5afc19e29834e9aa6be29a8ea59a2c9785 |
| Install bat | 16b9a7358be88632378ba20ba1430786f3b844694b1f876211ecdbecf5cccbc2 |
| Install bat | 37b485ed8d150d022c41e5e307b8c54c34ef806625b44d0c940b18be7d5b29ce |
| Install bat | 3e2a0bafbd44e24b17fd7b17c9f2b2a3727349971d42612d55bbc1732082619a |
| Install bat | 8c29f9189a9ad75a959024f59e68c62d42a6fd42f9eacf847128c7efe4ef7578 |
| Install bat | bd699ed720e2bd7085b3444cb8f4d36870b5b48df1055ec6cc1553db3eef7faf |
| Install bat | a6b5448ba45f3f352f5f4c5376024891adda1ef8ebf62a8fe63424fa230c691d |
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





