APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting

APT41/Silver Dragon Expanding Enterprise Attack Surface (TL-2026-0292), also tracked as Silver Dragon Campaign, is a high-severity advanced persistent threat campaign scored CVSS 8.5, first published 2026-03-27. It is attributed to APT41 (China) with high confidence, affects Ivanti Endpoint Manager Mobile (EPMM), references 6 CVEs (CVE-2025-4427, CVE-2025-4428, CVE-2021-44228), maps to 43 MITRE ATT&CK techniques (T1003, T1014, T1018), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-0292

Threat ID
TL-2026-0292
Also known as
Silver Dragon Campaign, APT41 Enterprise Expansion 2026
Severity
HIGH
CVSS
8.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
APT
First published
2026-03-27
Last reviewed
2026-03-27
Attribution
APT41
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government, healthcare, telecommunications, technology, finance, education, defense
Target regions
Europe, Southeast Asia, Uzbekistan, North America, East Asia
Detection rules
9
Indicators of compromise
30

Malware and tooling in APT41/Silver Dragon Expanding Enterprise Attack Surface

Malware and tooling: BamboLoader, DUSTPAN - S1158, DUSTTRAP - S1159, GearDoor, KEYPLUG, MonikerLoader, PlugX, SSHcmd, ShadowPad, SilverScreen, TOUGHPROGRESS, Cobalt Strike

China-linked APT41 and its Silver Dragon subgroup are actively targeting government entities in Europe and Southeast Asia using novel tooling including GearDoor (Google Drive C2), BamboLoader, MonikerLoader, and SilverScreen. The group exploits public-facing applications including Ivanti EPMM (CVE-2025-4427/CVE-2025-4428), conducts spear-phishing with weaponized LNK files, hijacks Windows services for persistence, and leverages AppDomain hijacking and DLL side-loading for defense evasion.

How APT41/Silver Dragon Expanding Enterprise Attack Surface works

APT41 (also tracked as Brass Typhoon, Wicked Panda, and BARIUM) is a prolific China-linked threat actor conducting both state-sponsored espionage and financially motivated operations. In March 2026, Check Point Research disclosed the activities of Silver Dragon, a previously unreported APT41 subgroup actively targeting government entities in Europe and Southeast Asia since mid-2024.

Silver Dragon employs three distinct delivery chains to deploy payloads. The first uses AppDomain hijacking: a RAR archive containing a batch script that executes MonikerLoader, a heavily obfuscated .NET-based loader that decrypts and executes a Cobalt Strike beacon directly in memory. The second chain deploys BamboLoader, a C++ shellcode DLL loader registered as a Windows service, which decrypts and decompresses shellcode staged on disk before injecting it into the legitimate Windows process taskhost.exe. The third chain targets victims via spear-phishing emails with weaponized LNK attachments — primarily targeting Uzbekistan — that trigger PowerShell execution, launching GameHook.exe (a legitimate executable vulnerable to DLL side-loading) which loads graphics-hook-filter64.dll to decrypt and execute the payload stored in simhei.dat.

A key innovation in the Silver Dragon toolset is GearDoor, a .NET backdoor that uses Google Drive as its command-and-control channel. GearDoor authenticates to attacker-controlled Google Drive accounts and uses file extensions as task indicators: PNG files serve as heartbeat beacons with system information, PDF files trigger command execution and directory operations, CAB files enable host enumeration and process listing, RAR files execute payloads (self-updating if named wiatrace.bak), and 7Z files trigger in-memory plugin execution. All communications are encrypted before transmission to the cloud storage C2.

Additional post-exploitation tools include SilverScreen, a .NET screen-monitoring tool that captures periodic screenshots with cursor positioning and compresses them for exfiltration, and SSHcmd, a .NET SSH utility providing remote command execution and file transfer capabilities.

APT41 has a long history of exploiting public-facing applications for initial access. Recent campaigns have exploited Ivanti Endpoint Manager Mobile zero-days (CVE-2025-4427 authentication bypass and CVE-2025-4428 remote code execution), alongside historical exploitation of Log4Shell (CVE-2021-44228), Microsoft Exchange ProxyLogon (CVE-2021-26855), Citrix ADC (CVE-2019-19781), and Zoho ManageEngine (CVE-2020-10189).

The group's expanding attack surface now spans cloud workloads, supply chains, remote devices, and operational technology environments. Cobalt Strike beacons deployed by Silver Dragon are configured for multiple C2 channels including DNS tunneling, HTTP via Cloudflare CDN, and SMB communication for intra-network lateral movement. Analysis of recovered artifacts indicates the use of an automated payload generation framework, as all files within initial archives share identical creation timestamps. A recovered log file documented per-attack configuration parameters including file paths, service names, encryption keys, and target processes.

Attribution to APT41 is established through post-exploitation script overlap with known APT41 activity and through BamboLoader decryption mechanisms that match previously documented China-nexus APT shellcode loaders. The group has deployed over 30 malware families across campaigns, including KEYPLUG, DUSTPAN, DUSTTRAP, ShadowPad, PlugX, Winnti, and TOUGHPROGRESS.

MITRE ATT&CK techniques used in TL-2026-0292

credential-access

T1003 OS Credential Dumping; T1110 Brute Force

defense-evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1078 Valid Accounts; T1134 Access Token Manipulation; T1140 Deobfuscate/Decode Files or Information; T1550 Use Alternate Authentication Material

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery

lateral-movement

T1021 Remote Services

execution

T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1569 System Services

exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

collection

T1056 Input Capture; T1113 Screen Capture; T1560 Archive Collected Data

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

initial-access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing

impact

T1486 Data Encrypted for Impact

persistence

T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

stealth

T1574 Hijack Execution Flow

resource-development

T1586 Compromise Accounts; T1588 Obtain Capabilities

reconnaissance

T1595 Active Scanning

Affected products and versions in APT41/Silver Dragon Expanding Enterprise Attack Surface

  • Ivanti — Endpoint Manager Mobile (EPMM)
    Vulnerable versions: prior to 11.12.0.5; 12.3.0.0-12.3.0.1; 12.4.0.0-12.4.0.1; 12.5.0.0
    Fixed in: 11.12.0.5+; 12.3.0.2+; 12.4.0.2+; 12.5.0.1+
  • Apache — Log4j
    Vulnerable versions: 2.0-beta9 to 2.14.1
    Fixed in: 2.15.0+; 2.17.1+
  • Microsoft — Exchange Server
    Vulnerable versions: 2013; 2016; 2019
    Fixed in: March 2021 Security Update
  • Citrix — ADC / Gateway
    Vulnerable versions: 10.5; 11.1; 12.0; 12.1; 13.0
    Fixed in: Patched firmware releases
  • Zoho — ManageEngine Desktop Central
    Vulnerable versions: prior to build 10.0.474
    Fixed in: 10.0.474+
  • Microsoft — Windows (all versions)
    Vulnerable versions: Windows 10/11, Server 2016-2025
    Fixed in: N/A — mitigate via endpoint protection

Remediation for APT41/Silver Dragon Expanding Enterprise Attack Surface

Patches

  • Apply Ivanti EPMM patches for CVE-2025-4427 and CVE-2025-4428 (upgrade to 11.12.0.5+ or 12.3.0.2+)
  • Ensure Log4j remediation for CVE-2021-44228 across all Java applications
  • Apply Microsoft Exchange patches for CVE-2021-26855 (ProxyLogon)
  • Patch Citrix ADC/Gateway for CVE-2019-19781
  • Patch Zoho ManageEngine for CVE-2020-10189

Immediate actions

  • Block known APT41 C2 infrastructure at perimeter firewalls and DNS resolvers
  • Audit all Ivanti EPMM instances for CVE-2025-4427/CVE-2025-4428 exploitation indicators
  • Monitor Google Drive API activity for anomalous file creation patterns matching GearDoor C2 protocol
  • Scan for MonikerLoader, BamboLoader, and GearDoor artifacts on endpoints
  • Review Windows services for unauthorized DLL registrations and service hijacking
  • Block execution of GameHook.exe and associated DLL side-loading chains

Workarounds

  • Restrict Google Drive API access to approved applications only
  • Disable PowerShell for non-administrative users
  • Block LNK file execution from email attachments at mail gateway
  • Implement WDAC or AppLocker policies to prevent unsigned DLL loading
  • Monitor for RAR archives with identical file creation timestamps

Longer-term hardening

  • Deploy EDR with behavioral detection for AppDomain hijacking and in-memory payload execution
  • Implement application allowlisting to prevent unauthorized .NET assembly loading
  • Enforce cloud storage DLP policies to detect C2 abuse of Google Drive and OneDrive
  • Segment networks to limit Cobalt Strike SMB lateral movement
  • Implement DNS monitoring for tunneling detection and anomalous query patterns
  • Conduct threat hunting for APT41 TTPs across enterprise using MITRE ATT&CK framework

CVEs associated with APT41/Silver Dragon Expanding Enterprise Attack Surface

CVE-2025-4427, CVE-2025-4428, CVE-2021-44228, CVE-2021-26855, CVE-2019-19781, CVE-2020-10189

Weaknesses (CWE) in APT41/Silver Dragon Expanding Enterprise Attack Surface

CWE-288, CWE-94, CWE-502, CWE-917, CWE-22, CWE-78

Timeline of APT41/Silver Dragon Expanding Enterprise Attack Surface

  • U.S. DOJ unseals indictments against APT41 members for computer intrusion campaigns targeting over 100 organizations globally
  • APT41 exploits CVE-2020-10189 (Zoho ManageEngine) to deploy Cobalt Strike beacons against legal and financial sector targets
  • APT41 exploits CVE-2021-26855 (Microsoft Exchange ProxyLogon) as part of mass exploitation campaign targeting government and private sector
  • APT41 rapidly weaponizes CVE-2021-44228 (Log4Shell) for initial access across multiple target sectors
  • Silver Dragon subgroup begins active operations targeting government entities in Europe and Southeast Asia with novel tooling
  • CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (RCE) disclosed for Ivanti Endpoint Manager Mobile; APT41 observed exploiting in the wild
  • Google Cloud Threat Intelligence publishes analysis of APT41 innovative tactics including TOUGHPROGRESS malware and Google Calendar C2 channel
  • CISA adds CVE-2025-4427 and CVE-2025-4428 to Known Exploited Vulnerabilities catalog with June 9 remediation deadline
  • The Hacker News and Security Affairs publish coverage of Silver Dragon campaign and APT41 Google Drive C2 capabilities
  • Check Point Research publishes detailed analysis of Silver Dragon subgroup revealing GearDoor, BamboLoader, MonikerLoader, SilverScreen, and SSHcmd tooling
  • Threadlinqs Intelligence Platform publishes comprehensive threat profile TL-2026-0292 covering APT41/Silver Dragon campaign
  • Cyble publishes enterprise attack surface analysis detailing APT41 expanding targeting across cloud, supply chain, OT, and remote device environments
  • As of 2026-05-29, APT41/Silver Dragon remains a live, ongoing threat: Check Point disclosed the GearDoor/BamboLoader toolset only in March 2026, with parallel APT41 cloud-credential and TOUGHPROGRESS campaigns running into Q2 2026. The actor is undeterred by 2019/2020 US indictments (no 2026 arrests/takedowns), and its Ivanti EPMM attack surface keeps expanding—new CVE-2026-1281/1340 added to CISA KEV alongside still-exploited CVE-2025-4427/4428.

Sources cited for APT41/Silver Dragon Expanding Enterprise Attack Surface

Threats related to APT41/Silver Dragon Expanding Enterprise Attack Surface

Detection coverage for TL-2026-0292

As of 2026-03-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0292 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats