Operation Dragon Whistle: UNG002 Targets Chinese Academia via Weaponized Institutional Lure

May 21, 2026, 4:49 p.m.

Description

A sophisticated spear-phishing campaign designated Operation Dragon Whistle has been identified targeting Changzhou University in China. The threat actor UNG002 leveraged highly contextual social engineering by impersonating official university communications regarding mandatory 2026 National Student Physical Fitness and Health Standards testing, which directly impacts graduation eligibility. The attack chain begins with a weaponized ZIP file containing a malicious LNK file disguised as a PDF document. Upon execution, it triggers a VBScript that simultaneously displays a legitimate-looking decoy document while deploying a multi-stage infection chain involving DLL sideloading via Bandizip.exe, anti-debugging techniques, and ultimately delivering a Cobalt Strike Beacon payload entirely in memory. The campaign demonstrates advanced evasion capabilities and utilizes Chinese cloud infrastructure hosted on Alibaba Cloud for command and control operations.

Date

  • Created: May 20, 2026, 1:07 p.m.
  • Published: May 20, 2026, 1:07 p.m.
  • Modified: May 21, 2026, 4:49 p.m.

Indicators

  • e7aff6a55a7866776272d9913dfbf9d7db33fc9de6aced22f2a195feebb0e85f
  • cd99e83d241cfbb41bfcd0bc622a87d16268e710ca7d736d0c5f44774e0056e2
  • c937eca7c4c9b98df9257d986e666d25411aac5fa39d21f7018dd2e1663f0c76
  • ed7087e3afba4b320bdf04f32d3a6c567effd3d18a97682968e567000e70b335
  • 35a478f53f64bd412f374c65360fdba0518749537193669a8fe08d14bed65a2a
  • eb14d9e35a3bf0a933297f861bee0be9e6b9061fe4573a81ac92b71d55b6474f
  • fe11b199ada23d5ac25efc4215e67f4ff617ccb4d429eb64412072687367ca1c
  • 60.205.186.162

Attack Patterns

  • Cobalt Strike - S0154
  • UNG002

Additional Informations

  • Education
  • lysander.asia
  • China