APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting — Threadlinqs Intelligence
As of 2026-05-30, APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting is a high-severity apt threat attributed to APT41 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0292 · Severity: HIGH · CVSS: 8.5 · Status: ACTIVE · Category: APT
Attribution: APT41 · China · ESPIONAGE
China-linked APT41 and its Silver Dragon subgroup are actively targeting government entities in Europe and Southeast Asia using novel tooling including GearDoor (Google Drive C2), BamboLoader,
APT41 (also tracked as Brass Typhoon, Wicked Panda, and BARIUM) is a prolific China-linked threat actor conducting both state-sponsored espionage and financially motivated operations. In March 2026, Check Point Research disclosed the activities of Silver Dragon, a previously unreported APT41 subgroup actively targeting government entities in Europe and Southeast Asia since mid-2024.
Silver Dragon employs three distinct delivery chains to deploy payloads. The first uses AppDomain hijacking: a RAR archive containing a batch script that executes MonikerLoader, a heavily obfuscated .NET-based loader that decrypts and executes a Cobalt Strike beacon directly in memory. The second chain deploys BamboLoader, a C++ shellcode DLL loader registered as a Windows service, which decrypts and decompresses shellcode staged on disk before injecting it into the legitimate Windows process taskhost.exe. The third chain targets victims via spear-phishing emails with weaponized LNK attachments — primarily targeting Uzbekistan — that trigger PowerShell execution, launching GameHook.exe (a legitimate executable vulnerable to DLL side-loading) which loads graphics-hook-filter64.dll to decrypt and execute the payload stored in simhei.dat.
A key innovation in the Silver Dragon toolset is GearDoor, a .NET backdoor that uses Google Drive as its command-and-control channel. GearDoor authenticates to attacker-controlled Google Drive accounts and uses file extensions as task indicators: PNG files serve as heartbeat beacons with system information, PDF files trigger command execution and directory operations, CAB files enable host enumeration and process listing, RAR files execute payloads (self-updating if named wiatrace.bak), and 7Z files trigger in-memory plugin execution. All communications are encrypted before transmission to the cloud storage C2.
Additional post-exploitation tools include SilverScreen, a .NET screen-monitoring tool that captures periodic screenshots with cursor positioning and compresses them for exfiltration, and SSHcmd, a .NET SSH utility providing remote command execution and file transfer capabilities.
APT41 has a long history of exploiting public-facing applications for initial access. Recent campaigns have exploited Ivanti Endpoint Manager Mobile zero-days (CVE-2025-4427 authentication bypass and CVE-2025-4428 remote code execution), alongside historical exploitation of Log4Shell (CVE-2021-44228), Microsoft Exchange ProxyLogon (CVE-2021-26855), Citrix ADC (CVE-2019-19781), and Zoho ManageEngine (CVE-2020-10189).
The group's expanding attack surface now spans cloud workloads, supply chains, remote devices, and operational technology environments. Cobalt Strike beacons deployed by Silver Dragon are configured for multiple C2 channels including DNS tunneling, HTTP via Cloudflare CDN, and SMB communication for intra-network lateral movement. Analysis of recovered artifacts indicates the use of an automated payload generation framework, as all files within initial archives share identical creation timestamps. A recovered log file documented per-attack configuration parameters including file paths, service names, encryption keys, and target processes.
Attribution to APT41 is established through post-exploitation script overlap with known APT41 activity and through BamboLoader decryption mechanisms that match previously documented China-nexus APT shellcode loaders. The group has deployed over 30 malware families across campaigns, including KEYPLUG, DUSTPAN, DUSTTRAP, ShadowPad, PlugX, Winnti, and TOUGHPROGRESS.
Weaknesses (CWE)
CWE-288, CWE-94, CWE-502, CWE-917, CWE-22, CWE-78
Target sectors: government, healthcare, telecommunications, technology, finance, education, defense
Target regions: Europe, Southeast Asia, Uzbekistan, North America, East Asia
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2025-4427, CVE-2025-4428, CVE-2021-44228, CVE-2021-26855, CVE-2019-19781, CVE-2020-10189, T1190, T1566, T1195, T1078, T1059, T1059, T1569, T1047, T1574, T1574