Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Operation Dragon Whistle: UNG002 Targets Chinese Academia via Weaponized Institutional Lure

eb14d9e35a3bf0a933297f861bee0be9e6b9061fe4573a81ac92b71d55b6474f

TLP:CLEAR
Active

SHA-256 Hash

Description

A sophisticated spear-phishing campaign designated Operation Dragon Whistle has been identified targeting Changzhou University in China. The threat actor UNG002 leveraged highly contextual social engineering by impersonating official university communications regarding mandatory 2026 National Student Physical Fitness and Health Standards testing, which directly impacts graduation eligibility. The attack chain begins with a weaponized ZIP file containing a malicious LNK file disguised as a PDF document. Upon execution, it triggers a VBScript that simultaneously displays a legitimate-looking decoy document while deploying a multi-stage infection chain involving DLL sideloading via Bandizip.exe, anti-debugging techniques, and ultimately delivering a Cobalt Strike Beacon payload entirely in memory. The campaign demonstrates advanced evasion capabilities and utilizes Chinese cloud infrastructure hosted on Alibaba Cloud for command and control operations.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Operation Dragon Whistle: UNG002 Targets Chinese Academia via Weaponized Institutional Lure
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:41
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of eb14d9e35a3bf0a933297f861bee0be9e6b9061fe4573a81ac92b71d55b6474f

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.