Silver Dragon Uses Google Drive as Command Channel
The Silver Dragon group, linked to China, uses Google Drive to orchestrate covert communication targeting Europe and Asia. As part of the APT41 umbrella, Silver Dragon exploits vulnerabilities in public internet servers and uses phishing emails with malicious attachments to infiltrate systems. After gaining access, the group utilizes the commercial tool Cobalt Strike for maintaining control of infected machines through DNS tunneling.
Check Point analysts identified infection chains used by Silver Dragon, with Cobalt Strike being delivered as the final payload. Silver Dragon employs GearDoor, a tool leveraging Google Drive, avoiding security flags typically raised by dedicated servers. This backdoor facilitates command and control via file uploads and downloads, complicating detection efforts.
Organizations should scrutinize Google Drive traffic for anomalies and secure Windows services against mimicry. By monitoring these activities and enhancing phishing training, firms can better defend against such invasive threats. For a comprehensive account, read the full article here:
https://cybersecuritynews.com/silver-dragon-apt-group/
