“We are about to land.” : How CloudDragon Turns a Nightmare into Reality

2021-05-07 • Team T5 •

https://i.blackhat.com/asia-21/Friday-Handouts/as-21-Kuo-We-Are-About-To-Land-How-CloudDragon-Turns-A-Nightmare-Into-Reality.pdf

Attachments

as-21-Kuo-We-Are-About-To-Land-How-CloudDragon-Turns-A-Nightmare-I_2d4Ribw.pdf (11 MB)

Thumbnail for “We are about to land.” : How CloudDragon Turns a Nightmare into Reality

The CloudDragon report describes an APT intrusion playbook built around supply-chain compromise, phishing, and mobile targeting. The presentation highlights malware and tooling associated with the activity, including JamBog or AppleSeed, DongMulRAT, GoldDragon variants, FlowerPower, and NavRAT-related capabilities. It frames the campaign as a multi-stage threat that uses social engineering and compromised software channels to reach targets before deploying payloads and collecting intelligence from victim systems.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0e2e8be594220513b198f9507eedd95… 2021-05-07 2021-05-07

Related Actors

Related Reports

« Back