Silver Dragon: How APT41’s Newest Subgroup Uses Google Drive to Hide in Plain Sight
Mar 4, 2026 // 12:32 - Norina Velotta


Silver Dragon, a sophisticated threat cluster linked to APT41, is currently targeting government entities across Southeast Asia and Europe. Active since mid-2024, the group utilizes a mix of public-facing server exploitation and phishing to deploy its specialized toolkit.

Key Tactics and Tools

  • Initial Access: Entry is gained via spear-phishing or exploiting internet-facing servers.
  • Cobalt Strike: They deploy beacons for initial reconnaissance and persistent remote access.
  • GearDoor Backdoor: This custom malware uses Google Drive as its command-and-control (C2) channel, allowing malicious traffic to hide within legitimate cloud service communications.
  • Persistence: The group hijacks Windows services and abuses the .NET AppDomain Manager to load malicious assemblies, blending into normal system activity.

Specialized Toolkit

Researchers at Check Point Research identified several custom post-exploitation tools:

  • SSHcmd: A command-line utility acting as an SSH wrapper for file transfers.
  • SliverScreen: A tool that takes periodic screenshots of the victim’s desktop.
  • DNS Tunneling: Used to evade traditional network-level detection.

APT41 Connection

Silver Dragon is part of the broader APT41 (Winnti) umbrella, which is known for its dual focus on state-sponsored espionage and financial gain. This campaign follows a documented trend of APT41-linked actors abusing legitimate platforms like Google Calendar and Google Sheets for stealthy C2 operations.

#apt41’s  #dragon:  #drive  #google  #hide  #how  #newest  #news  #plain  #sight  #silver  #subgroup  #uses   —   News