China-aligned (unattributed)
China-aligned (specific group attribution not publicly established) · Espionage / intelligence collection
Tactics, Techniques & Procedures (TTPs)
- Spear-phishing via ZIP-compressed LNK (Windows Shortcut) files disguised as PDF documents
- Rust-based loader for in-memory payload execution, minimising on-disk artefacts
- AZUREVEIL implant (AdaptixC2 agent): C2 via Microsoft Azure Blob Storage — both attacker and implant communicate via shared container, generating no direct adversary connections
- Azure Blob Storage C2: network traffic structurally identical to legitimate Microsoft 365 activity, invisible to perimeter controls trusting cloud provider traffic
- Cobalt Strike deployment (more recent iterations) substituting AdaptixC2 for operational flexibility
- Beacon Object File (BOF) execution in-memory via AZUREVEIL's 36 built-in post-exploitation commands
Known Targets
Analyst Notes
Identified by Seqrite researchers in June 2026 as Operation Dragon Weave. Attribution to a specific named Chinese APT cluster has not been publicly established; the targeting pattern — European government and research institutions alongside Taiwan financial and technology entities — is consistent with MSS collection priorities. The Azure Blob Storage C2 technique represents the leading edge of a broader trend in which APT actors route adversary traffic through legitimate cloud provider infrastructure to evade network monitoring. Organisations whose security tooling exempts Microsoft Azure, Google Cloud, or GitHub from deep inspection are blind to this class of attack. Geographic expansion from 2026 (Cambodia, South Korea) suggests an active, well-resourced operation broadening scope.
Also Known As