Silver Dragon, an emerging China-linked threat actor assessed as part of the APT41 ecosystem, has conducted cyberespionage operations against government entities in Europe and Southeast Asia since at least mid-2024. Reporting based on Check Point research says the group gains initial access through a mix of exploitation of public-facing servers and phishing emails with malicious attachments, then blends into normal activity by hijacking legitimate Windows services for persistence and command-and-control (C2).
The activity includes a toolchain that uses heavily obfuscated loaders (including MonikerLoader and BamboLoader) to decrypt and inject payloads in memory, with Cobalt Strike beacons commonly deployed as a final-stage payload. Check Point also observed Google Drive-based C2 as an evasion technique, alongside Cobalt Strike configurations that can use DNS tunneling, HTTP via Cloudflare, or SMB for internal communications; additional custom post-exploitation tooling (e.g., screenshot capture utilities) was also reported, and artifacts suggested an automated framework for generating per-target attack packages (e.g., consistent file timestamps and recovered configuration logs with paths, service names, keys, and injected processes).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Check Point Research disclosed the Silver Dragon activity cluster, detailing its infection chains, custom tools including SilverScreen and SSHcmd, and assessing that the operation is tied to the China-linked APT41 ecosystem based on tradecraft overlaps.
The group used a custom .NET backdoor called GearDoor that communicated through a dedicated Google Drive account, alongside other C2 methods such as DNS tunneling, HTTP via Cloudflare, and SMB to blend malicious traffic with trusted services.
After access, the actor used AppDomain hijacking and malicious service DLL deployment to abuse legitimate Windows services for persistence and stealth, while delivering obfuscated loaders such as MonikerLoader and BamboLoader that ultimately installed Cobalt Strike.
Across observed campaigns, the group gained entry through phishing emails with malicious attachments, including weaponized LNK files, and by exploiting vulnerable public-facing servers.
A China-linked espionage cluster dubbed Silver Dragon, assessed as tied to the broader APT41 nexus, has been active since at least mid-2024 against government and public sector entities in Europe and Southeast Asia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.