Threat reportAPTTL-2026-0540
Operation Dragon Whistle — UNG0002 Spear-Phishes Changzhou University via LNK + VBS + DLL Sideloading Chain Delivering Cobalt Strike Beacon
Operation Dragon Whistle (TL-2026-0540), also tracked as Operation Dragon Whistle, is a high-severity advanced persistent threat campaign, first published 2026-05-20. It is attributed to UNG0002 (China) with medium confidence, affects Bandisoft Bandizip, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 1UNG0002
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-0540
- Threat ID
- TL-2026-0540
- Also known as
- Operation Dragon Whistle, Dragon Whistle Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- UNG0002
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- education, academia, government
- Target regions
- China, East Asia
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Operation Dragon Whistle
Malware and tooling: Cobalt Strike Beacon, Bandizip, Cobalt Strike
How Operation Dragon Whistle works
Seqrite Labs disclosed Operation Dragon Whistle on 2026-05-20: a UNG0002 spear-phishing campaign targeting Changzhou University (常州大学) faculty and students with a weaponized ZIP impersonating the institution's mandatory 2026 National Student Physical Fitness and Health Standards testing notice. The infection chain — LNK (explorer.exe LOtL) → chromedo.vbs → Bandizip.exe (legitimate signed binary) sideloading ark.x64.dll → in-memory SFX loader → Cobalt Strike Beacon — beacons to lysander[.]asia / 60.205.186.162 hosted on Alibaba Cloud (AS37963). Attribution is medium-high confidence based on TTP overlap with Operation Cobalt Whisper.
On 2026-05-20, Seqrite Labs (Quick Heal Technologies) — authored by Dixit Panchal, Kartik Jivani, and Vaibhav Krushna Billade — disclosed Operation Dragon Whistle, a precision spear-phishing campaign attributed with medium-high confidence to threat actor UNG0002 targeting Mainland China's higher-education sector. The operation specifically singled out Changzhou University (常州大学) students and faculty, weaponizing the institution's mandatory 2026 National Student Physical Fitness and Health Standards (《国家学生体质健康标准》) testing cycle — a graduation-critical compliance event — as the social-engineering lure.
INITIAL ACCESS: A spear-phishing email was sent from the address 18115820617@163.com under the display name '牛牛 (Cow Cat)' using NetEase's free 163.com mail service, deliberately chosen to bypass enterprise mail security scrutiny applied to unknown external domains. The email carried a ZIP attachment named '常州大学2026年《国家学生体质健康标准》测试通知最终版.zip' (Changzhou University 2026 National Student Physical Fitness and Health Standards Testing Notice — Final Version). The body content referenced the graduation-critical nature of the fitness assessment, real staff names, direct phone numbers, an active QQ group ID, and the official institutional seal — indicating either insider knowledge or extensive open-source reconnaissance of the target environment.
ARCHIVE STRUCTURE & STAGE 1 (LNK): The ZIP contained a double-extension LNK file masquerading as a PDF ('常州大学2026年《国家学生体质健康标准》测试通知.pdf.lnk') at the archive root, plus payload files buried four folders deep in nested directories mimicking macOS metadata directory naming conventions to evade automated archive scanning. The LNK abused the legitimate explorer.exe binary to execute the next-stage VBScript — a living-off-the-land (LOtL) technique that avoids spawning wscript.exe or cscript.exe directly, both of which are commonly flagged by EDR solutions.
STAGE 2 (chromedo.vbs): A 1KB VBScript named chromedo.vbs orchestrated both deception and malicious execution simultaneously. It constructed absolute paths to the decoy PDF and the malicious Bandizip executable dynamically at runtime, immediately opened the decoy PDF (capturing the victim's attention with a full-fidelity replica of the official Changzhou University testing notice), waited 800ms for the PDF to render, then silently executed Bandizip.exe via ShellExecute with the 'open' verb and window style 1 — no visible window, no prompt, no user interaction.
STAGE 3 (DLL SIDELOADING — ark.x64.dll): The threat actor abused Bandizip — a legitimate, widely-used South Korean archive management application by Bandisoft — as a LOtL signed binary. A malicious DLL named ark.x64.dll was placed alongside Bandizip.exe in the same hidden directory. Upon execution, Bandizip.exe followed the standard Windows DLL search order and loaded the attacker-controlled ark.x64.dll from its local directory before checking trusted system paths, resulting in malicious code executing under a legitimate process context.
ANTI-ANALYSIS (CreateArk export): The DLL's exported function CreateArk implemented multi-layered evasion: timing-based debugger checks using GetTickCount, CheckRemoteDebuggerPresent, IsDebuggerPresent, and additional analysis evasion routines. The export resolved targeted process names at runtime using memory regions allocated via VirtualAlloc combined with custom decryption loops to keep sensitive strings out of plaintext. The DLL enumerated running processes via CreateToolhelp32Snapshot / Process32First / Process32Next and compared each process name against an internally reconstructed blacklist that included wireshark.exe, procmon.exe, tcpview.exe, dumpcap.exe, fiddler.exe, charles.exe, and additional reverse-engineering and monitoring utilities. If a match was detected, the malware terminated execution to avoid running in monitored or researcher-controlled environments.
STAGE 4 (SFX LOADER & AMSI/ETW BYPASS): After environmental validation, the malware decrypted an obfuscated SFX payload at runtime and dynamically loaded it into process memory without disk persistence. During execution, the unpacked SFX component interacted with Windows security mechanisms — Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) — to disrupt runtime scanning, logging, and telemetry generation, lowering visibility for antivirus and EDR solutions.
STAGE 5 (COBALT STRIKE BEACON): Following the AMSI/ETW bypasses, the SFX payload decrypted the final-stage component entirely in memory, revealing a Cobalt Strike Beacon (SHA256 ed7087e3afba4b320bdf04f32d3a6c567effd3d18a97682968e567000e70b335). The Beacon initialized its User-Agent configuration and attempted to establish C2 communication for outbound network connectivity, executing entirely in memory without an on-disk executable drop to minimize forensic visibility.
C2 INFRASTRUCTURE: The Cobalt Strike Beacon communicated with 60.205.186.162, which resolved to lysander[.]asia, hosted on Alibaba Cloud (AS37963 — Hangzhou Alibaba Advertising), active since 2026-04-06 and still live as of the 2026-05-19 report cutoff. The lysander[.]asia domain was registered through HiChina (万网), an Alibaba Cloud subsidiary serving the Chinese domestic market that requires Chinese identity verification. MX records pointed to Feishu (飞书), ByteDance's enterprise platform predominantly used within China — a significant attribution signal rarely seen in infrastructure operated by non-Chinese actors.
INFRASTRUCTURE PIVOTING: Seqrite identified approximately 20 related Bandizip-themed weaponized samples and additional LNK files sharing common machine IDs across multiple campaigns. All implants beaconed to similar C2 infrastructure registered under AS37963.
ATTRIBUTION (UNG0002 / MEDIUM-HIGH CONFIDENCE): UNG0002 was previously documented in Seqrite's Operation Cobalt Whisper campaign, which heavily leveraged malicious LNK files and obfuscated VBScript as the primary delivery mechanism — identical foundational TTPs to Dragon Whistle. The actor has shifted C2 infrastructure from Tencent Cloud (AS45090, used in Cobalt Whisper) to Alibaba Cloud (AS37963, used in Dragon Whistle) — a deliberate ASN rotation to evade ASN-based blocking. The shift to Mainland China academic targets represents an expansion of UNG0002's footprint beyond previously documented victims.
MITRE ATT&CK techniques used in TL-2026-0540
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.007 Masquerading: Double File Extension; T1497 Virtualization/Sandbox Evasion; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1564.001 Hide Artifacts: Hidden Files and Directories; T1620 Reflective Code Loading; T1622 Debugger Evasion
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1129 Shared Modules; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
stealth
T1218 System Binary Proxy Execution; T1574.001 DLL
Initial Access
T1566.001 Phishing: Spearphishing Attachment
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.004 Acquire Infrastructure: Server; T1585.002 Establish Accounts: Email Accounts; T1588.002 Obtain Capabilities: Tool
defense-impairment
Affected products and versions in Operation Dragon Whistle
- Bandisoft — Bandizip
Vulnerable versions: all (abused as LOtL signed binary; not a vulnerability in the product itself) - Microsoft — Windows
Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022
Remediation for Operation Dragon Whistle
Immediate actions
- Block C2 indicator 60.205.186.162 and domain lysander[.]asia at perimeter firewall, DNS sinkhole, and proxy egress
- Quarantine inbound mail from 18115820617@163.com and apply heightened scrutiny to all 163.com / NetEase free-mail senders carrying ZIP attachments addressed to .edu.cn / academic domains
- Hunt for SHA256 e7aff6a55a7866776272d9913dfbf9d7db33fc9de6aced22f2a195feebb0e85f (lure ZIP) and cd99e83d241cfbb41bfcd0bc622a87d16268e710ca7d736d0c5f44774e0056e2 (LNK) across mail gateways, file shares, and EDR telemetry
- Hunt for ark.x64.dll (SHA256 35a478f53f64bd412f374c65360fdba0518749537193669a8fe08d14bed65a2a) and any anomalous Bandizip.exe instances in non-standard paths
- Block execution of Bandizip.exe outside known software-deployment directories via WDAC / AppLocker
Workarounds
- Block .lnk attachments at mail gateway entirely where business case permits
- Disable Windows Script Host (HKLM\Software\Microsoft\Windows Script Host\Settings\Enabled = 0) on workstations that do not require legitimate VBScript
- Application allowlisting to deny unsigned/unfamiliar DLL loads next to known LOtL signed binaries (Bandizip.exe, vmnat.exe, OneDrive.exe, etc.)
Longer-term hardening
- Deploy EDR rules detecting explorer.exe spawning .vbs files from deeply-nested archive-extraction paths (4+ directories deep)
- Enable AMSI logging and ETW provider audit (Microsoft-Windows-Threat-Intelligence) to surface AMSI/ETW patching attempts in memory
- Restrict the Windows DLL search order via SafeDllSearchMode and per-process DLL redirection / SafeSearch policy
- Mandatory user-awareness training for academic staff/students on impersonation lures referencing institutional compliance events
- Implement attachment sandboxing for inbound mail from free-webmail providers (163.com, qq.com, yeah.net, sina.com) with double-extension detection (.pdf.lnk, .doc.lnk, .xlsx.lnk)
Weaknesses (CWE) in Operation Dragon Whistle
Timeline of Operation Dragon Whistle
- C2 infrastructure lysander[.]asia / 60.205.186.162 (Alibaba Cloud AS37963, HiChina nameservers, Feishu MX records) provisioned and goes live.
- UNG0002 prepares Changzhou University-themed lure document — full-fidelity replica of official 2026 National Student Physical Fitness and Health Standards testing notice, including real staff names, QQ group ID, and institutional seal.
- Seqrite Labs observes spear-phishing emails from 18115820617@163.com (display name '牛牛 Cow Cat') delivering ZIP attachment '常州大学2026年《国家学生体质健康标准》测试通知最终版.zip' to Changzhou University faculty and students.
- Seqrite identifies ~20 related Bandizip-themed weaponized samples and additional LNK files sharing common machine IDs, all beaconing to similar AS37963 infrastructure.
- Seqrite confirms strong TTP overlap with Operation Cobalt Whisper (LNK + obfuscated VBScript primary delivery) — attribution to UNG0002 assessed at medium-high confidence.
- Report cutoff: C2 infrastructure remains live and operational; lysander[.]asia still resolving to 60.205.186.162.
- Threadlinqs Intelligence Platform ingests Operation Dragon Whistle as TL-2026-0540 and begins continuous monitoring of UNG0002 infrastructure.
- Seqrite Labs publishes Operation Dragon Whistle technical analysis on the Seqrite blog (authors: Dixit Panchal, Kartik Jivani, Vaibhav Krushna Billade).
- As of 2026-05-29, Operation Dragon Whistle remains ACTIVE: disclosed only 10 days ago (2026-05-20) by Seqrite, its C2 (lysander[.]asia / 60.205.186.162, Alibaba Cloud) was live at report cutoff with no takedown, sinkhole, or arrest reported. Attributed actor UNG0002 is an established China-nexus espionage group still operating across Asia, and the Bandizip DLL-sideload + Cobalt Strike chain stays fully viable.
Sources cited for Operation Dragon Whistle
- Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
- MITRE ATT&CK T1574.002 — DLL Side-Loading
- MITRE ATT&CK T1566.001 — Spearphishing Attachment
- MITRE ATT&CK T1059.005 — Visual Basic
- MITRE ATT&CK T1620 — Reflective Code Loading
- MITRE ATT&CK G-Group reference — UNG0002 (tracking)
- Cobalt Strike — Adversary Simulation & Red Team Operations
Detection coverage for TL-2026-0540
As of 2026-05-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0540 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.