Operation DragonWhistle Targets Changzhou University with Malicious LNK Files
Key Takeaways A new cyber campaign, dubbed Operation DragonWhistle, has been identified targeting government entities in Pakistan. The attackers leveraged sophisticated phishing tactics, using both...
Key Takeaways
- A new cyber campaign, dubbed Operation DragonWhistle, has been identified targeting government entities in Pakistan.
- The attackers leveraged sophisticated phishing tactics, using both malicious Word documents and deceptive PDF files to initiate compromise.
- Uniquely, the threat actors weaponized Microsoft’s Visual Studio Code, transforming its remote tunnel feature into a covert remote access channel.
- The campaign bypassed traditional security by making malicious traffic appear legitimate through Microsoft’s cloud infrastructure.
Sophisticated Cyber Campaign Targets Pakistani Government
Cybersecurity experts are raising alarms following the discovery of a new, highly coordinated cyber operation aimed at government institutions across Pakistan. This campaign, now designated Operation DragonWhistle, employs advanced social engineering and novel exploitation techniques to gain persistent access to victim systems.
Table Of Content
The attack chain begins with meticulously crafted phishing emails designed to ensnare employees into opening malicious attachments. These attachments trigger a sequence of events engineered to establish stealthy, long-term access for the attackers.
Operation DragonWhistle features two distinct infection vectors, both supported by a shared backend infrastructure. One path utilizes a weaponized Microsoft Word document containing a hidden macro, while the other involves a deceptive PDF file that prompts users to install a fake software update. This dual-pronged approach enhances the attackers’ chances of success, even if one method is detected or thwarted.
What sets this operation apart is not merely its targeting of sensitive government entities, but the innovative tools and methods employed by the threat actors.
Analysts at JoeSecurity identified the campaign through sandbox submissions, revealing in a report shared with Cyber Security News (CSN) that the attackers repurposed Visual Studio Code, a widely trusted development environment, as a remote access mechanism. This ingenious move allowed their malicious activities to masquerade as ordinary developer traffic, thereby evading detection.
Operation DragonWhistle Leverages Malicious LNK Files and VS Code Tunnels
The phishing emails were expertly tailored to mimic internal communications from a consultant engaged in a government safety project. They contained specific references to project deliverables, such as ANPR system designs and CAD drawings, aligning perfectly with the professional context of the targeted organizations.
Furthermore, the sender’s name and title closely matched those of legitimate staff members, suggesting extensive prior reconnaissance by the attackers.
The primary attachment, a document named “CAD Reprot.doc,” contained an auto-executing macro. Upon opening, this macro silently downloaded an executable named code.exe from an attacker-controlled server. It then initiated Visual Studio Code tunnel commands in the background, completely unbeknownst to the user.
During this process, the macro intercepted a Microsoft device authentication code before the user could react. This code was subsequently transmitted to the attackers via a Discord webhook, granting them the necessary credentials to authenticate the compromised machine into a VS Code tunneling session under their control.
Once enrolled, the victim’s computer established a connection back to the attacker through Microsoft’s own cloud infrastructure, making the traffic appear entirely legitimate. From this point, the threat actor gained the ability to use the integrated terminal as a remote shell, execute commands, access files, and deploy additional tools directly onto the compromised system.
The PDF File and its Staged Payload
The secondary attachment, labeled “ANPR Reprot.pdf,” presented itself as an Adobe Reader error, instructing the user that their software required an update. A button within the document linked to a ClickOnce installation package, which was designed to impersonate a genuine Adobe product but lacked the proper authentication markers of legitimate software.
Researchers observed that the package exhibited an unusual versioning pattern and an all-zero public key token, clear indicators of a manually fabricated impersonation rather than an authentic software release. It was evidently designed to install a .NET-based application on the victim’s machine, serving as a subsequent stage in the attack chain.
By the time investigators delved deeper, the attacker’s hosting domain had been suspended, preventing the retrieval of the final payload. Nevertheless, based on the structure of the deployment manifest and the available file artifacts, the ultimate objective was most likely the execution of a concealed .NET program on the compromised system.
Organizations facing similar threats must remain vigilant against unexpected file attachments, even when they appear to originate from trusted or familiar contacts. Proactive monitoring of developer tools on non-developer workstations and flagging unusual authentication requests can significantly enhance security teams’ ability to detect such sophisticated attacks earlier in the kill chain.
What You Should Do
- Educate users on identifying sophisticated phishing attempts, especially those impersonating internal communications or software updates.
- Implement robust email filtering and attachment scanning solutions to detect malicious documents and executables.
- Restrict macro execution in Microsoft Office documents by default, and enforce strong application whitelisting policies.
- Monitor network traffic for unusual connections originating from developer tools like Visual Studio Code, especially on machines not used for software development.
- Enable multi-factor authentication (MFA) for all accounts, particularly for accessing cloud services and sensitive systems.
- Regularly review and audit authentication logs for suspicious device enrollments or unusual authentication requests.
- Keep all operating systems, applications, and security software updated to patch known vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.