# Operation Dragon Whistle — UNG0002 Spear-Phishes Changzhou University via LNK + VBS + DLL Sideloading Chain Delivering Cobalt Strike Beacon

> Seqrite Labs disclosed Operation Dragon Whistle on 2026-05-20: a UNG0002 spear-phishing campaign targeting Changzhou University (常州大学) faculty and students with a weaponized ZIP impersonating the institution's mandatory 2026 National Student Physical Fitness and Health Standards testing notice. The infection chain — LNK (explorer.exe LOtL) → chromedo.vbs → Bandizip.exe (legitimate signed binary) sideloading ark.x64.dll → in-memory SFX loader → Cobalt Strike Beacon — beacons to lysander[.]asia / 60.205.186.162 hosted on Alibaba Cloud (AS37963). Attribution is medium-high confidence based on TTP overlap with Operation Cobalt Whisper.

- **Published:** 2026-05-20T12:00:00Z
- **Last reviewed:** 2026-05-20T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0540
- **ID:** TL-2026-0540
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** UNG0002 (China)
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-05-20, Seqrite Labs (Quick Heal Technologies) — authored by Dixit Panchal, Kartik Jivani, and Vaibhav Krushna Billade — disclosed Operation Dragon Whistle, a precision spear-phishing campaign attributed with medium-high confidence to threat actor UNG0002 targeting Mainland China's higher-education sector. The operation specifically singled out Changzhou University (常州大学) students and faculty, weaponizing the institution's mandatory 2026 National Student Physical Fitness and Health Standards (《国家学生体质健康标准》) testing cycle — a graduation-critical compliance event — as the social-engineering lure.

INITIAL ACCESS: A spear-phishing email was sent from the address 18115820617@163.com under the display name '牛牛 (Cow Cat)' using NetEase's free 163.com mail service, deliberately chosen to bypass enterprise mail security scrutiny applied to unknown external domains. The email carried a ZIP attachment named '常州大学2026年《国家学生体质健康标准》测试通知最终版.zip' (Changzhou University 2026 National Student Physical Fitness and Health Standards Testing Notice — Final Version). The body content referenced the graduation-critical nature of the fitness assessment, real staff names, direct phone numbers, an active QQ group ID, and the official institutional seal — indicating either insider knowledge or extensive open-source reconnaissance of the target environment.

ARCHIVE STRUCTURE & STAGE 1 (LNK): The ZIP contained a double-extension LNK file masquerading as a PDF ('常州大学2026年《国家学生体质健康标准》测试通知.pdf.lnk') at the archive root, plus payload files buried four folders deep in nested directories mimicking macOS metadata directory naming conventions to evade automated archive scanning. The LNK abused the legitimate explorer.exe binary to execute the next-stage VBScript — a living-off-the-land (LOtL) technique that avoids spawning wscript.exe or cscript.exe directly, both of which are commonly flagged by EDR solutions.

STAGE 2 (chromedo.vbs): A 1KB VBScript named chromedo.vbs orchestrated both deception and malicious execution simultaneously. It constructed absolute paths to the decoy PDF and the malicious Bandizip executable dynamically at runtime, immediately opened the decoy PDF (capturing the victim's attention with a full-fidelity replica of the official Changzhou University testing notice), waited 800ms for the PDF to render, then silently executed Bandizip.exe via ShellExecute with the 'open' verb and window style 1 — no visible window, no prompt, no user interaction.

STAGE 3 (DLL SIDELOADING — ark.x64.dll): The threat actor abused Bandizip — a legitimate, widely-used South Korean archive management application by Bandisoft — as a LOtL signed binary. A malicious DLL named ark.x64.dll was placed alongside Bandizip.exe in the same hidden directory. Upon execution, Bandizip.exe followed the standard Windows DLL search order and loaded the attacker-controlled ark.x64.dll from its local directory before checking trusted system paths, resulting in malicious code executing under a legitimate process context.

ANTI-ANALYSIS (CreateArk export): The DLL's exported function CreateArk implemented multi-layered evasion: timing-based debugger checks using GetTickCount, CheckRemoteDebuggerPresent, IsDebuggerPresent, and additional analysis evasion routines. The export resolved targeted process names at runtime using memory regions allocated via VirtualAlloc combined with custom decryption loops to keep sensitive strings out of plaintext. The DLL enumerated running processes via CreateToolhelp32Snapshot / Process32First / Process32Next and compared each process name against an internally reconstructed blacklist that included wireshark.exe, procmon.exe, tcpview.exe, dumpcap.exe, fiddler.exe, charles.exe, and additional reverse-engineering and monitoring utilities. If a match was detected, the malware terminated execution to avoid running in monitored or researcher-controlled environments.

STAGE 4 (SFX LOADER & AMSI/ETW BYPASS): After environmental validation, the malware decrypted an obfuscated SFX payload at runtime and dynamically loaded it into process memory without disk persistence. During execution, the unpacked SFX component interacted with Windows security mechanisms — Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) — to disrupt runtime scanning, logging, and telemetry generation, lowering visibility for antivirus and EDR solutions.

STAGE 5 (COBALT STRIKE BEACON): Following the AMSI/ETW bypasses, the SFX payload decrypted the final-stage component entirely in memory, revealing a Cobalt Strike Beacon (SHA256 ed7087e3afba4b320bdf04f32d3a6c567effd3d18a97682968e567000e70b335). The Beacon initialized its User-Agent configuration and attempted to establish C2 communication for outbound network connectivity, executing entirely in memory without an on-disk executable drop to minimize forensic visibility.

C2 INFRASTRUCTURE: The Cobalt Strike Beacon communicated with 60.205.186.162, which resolved to lysander[.]asia, hosted on Alibaba Cloud (AS37963 — Hangzhou Alibaba Advertising), active since 2026-04-06 and still live as of the 2026-05-19 report cutoff. The lysander[.]asia domain was registered through HiChina (万网), an Alibaba Cloud subsidiary serving the Chinese domestic market that requires Chinese identity verification. MX records pointed to Feishu (飞书), ByteDance's enterprise platform predominantly used within China — a significant attribution signal rarely seen in infrastructure operated by non-Chinese actors.

INFRASTRUCTURE PIVOTING: Seqrite identified approximately 20 related Bandizip-themed weaponized samples and additional LNK files sharing common machine IDs across multiple campaigns. All implants beaconed to similar C2 infrastructure registered under AS37963.

ATTRIBUTION (UNG0002 / MEDIUM-HIGH CONFIDENCE): UNG0002 was previously documented in Seqrite's Operation Cobalt Whisper campaign, which heavily leveraged malicious LNK files and obfuscated VBScript as the primary delivery mechanism — identical foundational TTPs to Dragon Whistle. The actor has shifted C2 infrastructure from Tencent Cloud (AS45090, used in Cobalt Whisper) to Alibaba Cloud (AS37963, used in Dragon Whistle) — a deliberate ASN rotation to evade ASN-based blocking. The shift to Mainland China academic targets represents an expansion of UNG0002's footprint beyond previously documented victims.

## MITRE ATT&CK

- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1129 Shared Modules
- T1106 Native API
- T1218 System Binary Proxy Execution
- T1574.001 DLL
- T1036 Masquerading
- T1036.007 Masquerading: Double File Extension
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1027 Obfuscated Files or Information
- T1622 Debugger Evasion
- T1497 Virtualization/Sandbox Evasion
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1620 Reflective Code Loading
- T1685 Disable or Modify Tools
- T1057 Process Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1573 Encrypted Channel
- T1583.001 Acquire Infrastructure: Domains
- T1583.004 Acquire Infrastructure: Server
- T1585.002 Establish Accounts: Email Accounts
- T1588.002 Obtain Capabilities: Tool

## Sources

- [Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure](https://www.seqrite.com/blog/operation-dragon-whistle-ung002-targets-chinese-academia-via-weaponized-institutional-lure/)
- [MITRE ATT&CK T1574.002 — DLL Side-Loading](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK T1566.001 — Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001/)
- [MITRE ATT&CK T1059.005 — Visual Basic](https://attack.mitre.org/techniques/T1059/005/)
- [MITRE ATT&CK T1620 — Reflective Code Loading](https://attack.mitre.org/techniques/T1620/)
- [MITRE ATT&CK G-Group reference — UNG0002 (tracking)](https://attack.mitre.org/)
- [Cobalt Strike — Adversary Simulation & Red Team Operations](https://www.cobaltstrike.com/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0540
