APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting
APT41/Silver Dragon Expanding Enterprise Attack Surface (TL-2026-0292), also tracked as Silver Dragon Campaign, is a high-severity advanced persistent threat campaign scored CVSS 8.5, first published 2026-03-27. It is attributed to APT41 (China) with high confidence, affects Ivanti Endpoint Manager Mobile (EPMM), references 6 CVEs (CVE-2025-4427, CVE-2025-4428, CVE-2021-44228), maps to 43 MITRE ATT&CK techniques (T1003, T1014, T1018), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0292
- Threat ID
- TL-2026-0292
- Also known as
- Silver Dragon Campaign, APT41 Enterprise Expansion 2026
- Severity
- HIGH
- CVSS
- 8.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-27
- Last reviewed
- 2026-03-27
- Attribution
- APT41
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, healthcare, telecommunications, technology, finance, education, defense
- Target regions
- Europe, Southeast Asia, Uzbekistan, North America, East Asia
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in APT41/Silver Dragon Expanding Enterprise Attack Surface
Malware and tooling: BamboLoader, DUSTPAN - S1158, DUSTTRAP - S1159, GearDoor, KEYPLUG, MonikerLoader, PlugX, SSHcmd, ShadowPad, SilverScreen, TOUGHPROGRESS, Cobalt Strike
China-linked APT41 and its Silver Dragon subgroup are actively targeting government entities in Europe and Southeast Asia using novel tooling including GearDoor (Google Drive C2), BamboLoader, MonikerLoader, and SilverScreen. The group exploits public-facing applications including Ivanti EPMM (CVE-2025-4427/CVE-2025-4428), conducts spear-phishing with weaponized LNK files, hijacks Windows services for persistence, and leverages AppDomain hijacking and DLL side-loading for defense evasion.
How APT41/Silver Dragon Expanding Enterprise Attack Surface works
APT41 (also tracked as Brass Typhoon, Wicked Panda, and BARIUM) is a prolific China-linked threat actor conducting both state-sponsored espionage and financially motivated operations. In March 2026, Check Point Research disclosed the activities of Silver Dragon, a previously unreported APT41 subgroup actively targeting government entities in Europe and Southeast Asia since mid-2024.
Silver Dragon employs three distinct delivery chains to deploy payloads. The first uses AppDomain hijacking: a RAR archive containing a batch script that executes MonikerLoader, a heavily obfuscated .NET-based loader that decrypts and executes a Cobalt Strike beacon directly in memory. The second chain deploys BamboLoader, a C++ shellcode DLL loader registered as a Windows service, which decrypts and decompresses shellcode staged on disk before injecting it into the legitimate Windows process taskhost.exe. The third chain targets victims via spear-phishing emails with weaponized LNK attachments — primarily targeting Uzbekistan — that trigger PowerShell execution, launching GameHook.exe (a legitimate executable vulnerable to DLL side-loading) which loads graphics-hook-filter64.dll to decrypt and execute the payload stored in simhei.dat.
A key innovation in the Silver Dragon toolset is GearDoor, a .NET backdoor that uses Google Drive as its command-and-control channel. GearDoor authenticates to attacker-controlled Google Drive accounts and uses file extensions as task indicators: PNG files serve as heartbeat beacons with system information, PDF files trigger command execution and directory operations, CAB files enable host enumeration and process listing, RAR files execute payloads (self-updating if named wiatrace.bak), and 7Z files trigger in-memory plugin execution. All communications are encrypted before transmission to the cloud storage C2.
Additional post-exploitation tools include SilverScreen, a .NET screen-monitoring tool that captures periodic screenshots with cursor positioning and compresses them for exfiltration, and SSHcmd, a .NET SSH utility providing remote command execution and file transfer capabilities.
APT41 has a long history of exploiting public-facing applications for initial access. Recent campaigns have exploited Ivanti Endpoint Manager Mobile zero-days (CVE-2025-4427 authentication bypass and CVE-2025-4428 remote code execution), alongside historical exploitation of Log4Shell (CVE-2021-44228), Microsoft Exchange ProxyLogon (CVE-2021-26855), Citrix ADC (CVE-2019-19781), and Zoho ManageEngine (CVE-2020-10189).
The group's expanding attack surface now spans cloud workloads, supply chains, remote devices, and operational technology environments. Cobalt Strike beacons deployed by Silver Dragon are configured for multiple C2 channels including DNS tunneling, HTTP via Cloudflare CDN, and SMB communication for intra-network lateral movement. Analysis of recovered artifacts indicates the use of an automated payload generation framework, as all files within initial archives share identical creation timestamps. A recovered log file documented per-attack configuration parameters including file paths, service names, encryption keys, and target processes.
Attribution to APT41 is established through post-exploitation script overlap with known APT41 activity and through BamboLoader decryption mechanisms that match previously documented China-nexus APT shellcode loaders. The group has deployed over 30 malware families across campaigns, including KEYPLUG, DUSTPAN, DUSTTRAP, ShadowPad, PlugX, Winnti, and TOUGHPROGRESS.
MITRE ATT&CK techniques used in TL-2026-0292
credential-access
T1003 OS Credential Dumping; T1110 Brute Force
defense-evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1078 Valid Accounts; T1134 Access Token Manipulation; T1140 Deobfuscate/Decode Files or Information; T1550 Use Alternate Authentication Material
discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery
lateral-movement
execution
T1047 Windows Management Instrumentation; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1569 System Services
exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
collection
T1056 Input Capture; T1113 Screen Capture; T1560 Archive Collected Data
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
initial-access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing
impact
T1486 Data Encrypted for Impact
persistence
T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
stealth
resource-development
T1586 Compromise Accounts; T1588 Obtain Capabilities
reconnaissance
Affected products and versions in APT41/Silver Dragon Expanding Enterprise Attack Surface
- Ivanti — Endpoint Manager Mobile (EPMM)
Vulnerable versions: prior to 11.12.0.5; 12.3.0.0-12.3.0.1; 12.4.0.0-12.4.0.1; 12.5.0.0
Fixed in: 11.12.0.5+; 12.3.0.2+; 12.4.0.2+; 12.5.0.1+ - Apache — Log4j
Vulnerable versions: 2.0-beta9 to 2.14.1
Fixed in: 2.15.0+; 2.17.1+ - Microsoft — Exchange Server
Vulnerable versions: 2013; 2016; 2019
Fixed in: March 2021 Security Update - Citrix — ADC / Gateway
Vulnerable versions: 10.5; 11.1; 12.0; 12.1; 13.0
Fixed in: Patched firmware releases - Zoho — ManageEngine Desktop Central
Vulnerable versions: prior to build 10.0.474
Fixed in: 10.0.474+ - Microsoft — Windows (all versions)
Vulnerable versions: Windows 10/11, Server 2016-2025
Fixed in: N/A — mitigate via endpoint protection
Remediation for APT41/Silver Dragon Expanding Enterprise Attack Surface
Patches
- Apply Ivanti EPMM patches for CVE-2025-4427 and CVE-2025-4428 (upgrade to 11.12.0.5+ or 12.3.0.2+)
- Ensure Log4j remediation for CVE-2021-44228 across all Java applications
- Apply Microsoft Exchange patches for CVE-2021-26855 (ProxyLogon)
- Patch Citrix ADC/Gateway for CVE-2019-19781
- Patch Zoho ManageEngine for CVE-2020-10189
Immediate actions
- Block known APT41 C2 infrastructure at perimeter firewalls and DNS resolvers
- Audit all Ivanti EPMM instances for CVE-2025-4427/CVE-2025-4428 exploitation indicators
- Monitor Google Drive API activity for anomalous file creation patterns matching GearDoor C2 protocol
- Scan for MonikerLoader, BamboLoader, and GearDoor artifacts on endpoints
- Review Windows services for unauthorized DLL registrations and service hijacking
- Block execution of GameHook.exe and associated DLL side-loading chains
Workarounds
- Restrict Google Drive API access to approved applications only
- Disable PowerShell for non-administrative users
- Block LNK file execution from email attachments at mail gateway
- Implement WDAC or AppLocker policies to prevent unsigned DLL loading
- Monitor for RAR archives with identical file creation timestamps
Longer-term hardening
- Deploy EDR with behavioral detection for AppDomain hijacking and in-memory payload execution
- Implement application allowlisting to prevent unauthorized .NET assembly loading
- Enforce cloud storage DLP policies to detect C2 abuse of Google Drive and OneDrive
- Segment networks to limit Cobalt Strike SMB lateral movement
- Implement DNS monitoring for tunneling detection and anomalous query patterns
- Conduct threat hunting for APT41 TTPs across enterprise using MITRE ATT&CK framework
CVEs associated with APT41/Silver Dragon Expanding Enterprise Attack Surface
CVE-2025-4427, CVE-2025-4428, CVE-2021-44228, CVE-2021-26855, CVE-2019-19781, CVE-2020-10189
Weaknesses (CWE) in APT41/Silver Dragon Expanding Enterprise Attack Surface
CWE-288, CWE-94, CWE-502, CWE-917, CWE-22, CWE-78
Timeline of APT41/Silver Dragon Expanding Enterprise Attack Surface
- U.S. DOJ unseals indictments against APT41 members for computer intrusion campaigns targeting over 100 organizations globally
- APT41 exploits CVE-2020-10189 (Zoho ManageEngine) to deploy Cobalt Strike beacons against legal and financial sector targets
- APT41 exploits CVE-2021-26855 (Microsoft Exchange ProxyLogon) as part of mass exploitation campaign targeting government and private sector
- APT41 rapidly weaponizes CVE-2021-44228 (Log4Shell) for initial access across multiple target sectors
- Silver Dragon subgroup begins active operations targeting government entities in Europe and Southeast Asia with novel tooling
- CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (RCE) disclosed for Ivanti Endpoint Manager Mobile; APT41 observed exploiting in the wild
- Google Cloud Threat Intelligence publishes analysis of APT41 innovative tactics including TOUGHPROGRESS malware and Google Calendar C2 channel
- CISA adds CVE-2025-4427 and CVE-2025-4428 to Known Exploited Vulnerabilities catalog with June 9 remediation deadline
- The Hacker News and Security Affairs publish coverage of Silver Dragon campaign and APT41 Google Drive C2 capabilities
- Check Point Research publishes detailed analysis of Silver Dragon subgroup revealing GearDoor, BamboLoader, MonikerLoader, SilverScreen, and SSHcmd tooling
- Threadlinqs Intelligence Platform publishes comprehensive threat profile TL-2026-0292 covering APT41/Silver Dragon campaign
- Cyble publishes enterprise attack surface analysis detailing APT41 expanding targeting across cloud, supply chain, OT, and remote device environments
- As of 2026-05-29, APT41/Silver Dragon remains a live, ongoing threat: Check Point disclosed the GearDoor/BamboLoader toolset only in March 2026, with parallel APT41 cloud-credential and TOUGHPROGRESS campaigns running into Q2 2026. The actor is undeterred by 2019/2020 US indictments (no 2026 arrests/takedowns), and its Ivanti EPMM attack surface keeps expanding—new CVE-2026-1281/1340 added to CISA KEV alongside still-exploited CVE-2025-4427/4428.
Sources cited for APT41/Silver Dragon Expanding Enterprise Attack Surface
- Cyble: APT41 Enterprise Attack Surface and Cyber Risk Analysis
- The Hacker News: APT41-Linked Silver Dragon Targets Government Entities
- Security Affairs: From Phishing to Google Drive C2 — Silver Dragon Expands APT41 Playbook
- MITRE ATT&CK: APT41 Group Profile (G0096)
- Google Cloud Threat Intelligence: APT41 Innovative Tactics (TOUGHPROGRESS / Google Calendar C2)
- Darktrace: AI Caught APT41 Exploiting Zero-Day Vulnerability (CVE-2020-10189)
- Check Point Research: Silver Dragon — New APT41 Subgroup Targeting Governments
- NVD: CVE-2025-4427 — Ivanti EPMM Authentication Bypass
- NVD: CVE-2025-4428 — Ivanti EPMM Remote Code Execution
- CISA: Known Exploited Vulnerabilities Catalog — CVE-2025-4427/4428
Threats related to APT41/Silver Dragon Expanding Enterprise Attack Surface
- Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries
- SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign
- SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaign
- UAT-8099 (China) BadIIS Malware Campaign Targeting IIS Servers for SEO Fraud
- StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt Strike
Detection coverage for TL-2026-0292
As of 2026-03-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0292 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.