Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Operation Dragon Whistle: UNG002 Targets Chinese Academia via Weaponized Institutional Lure

60.205.186.162

TLP:CLEAR
Active

IPv4 Address

Description

A sophisticated spear-phishing campaign designated Operation Dragon Whistle has been identified targeting Changzhou University in China. The threat actor UNG002 leveraged highly contextual social engineering by impersonating official university communications regarding mandatory 2026 National Student Physical Fitness and Health Standards testing, which directly impacts graduation eligibility. The attack chain begins with a weaponized ZIP file containing a malicious LNK file disguised as a PDF document. Upon execution, it triggers a VBScript that simultaneously displays a legitimate-looking decoy document while deploying a multi-stage infection chain involving DLL sideloading via Bandizip.exe, anti-debugging techniques, and ultimately delivering a Cobalt Strike Beacon payload entirely in memory. The campaign demonstrates advanced evasion capabilities and utilizes Chinese cloud infrastructure hosted on Alibaba Cloud for command and control operations.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Operation Dragon Whistle: UNG002 Targets Chinese Academia via Weaponized Institutional Lure
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:42
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 60.205.186.162

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.