INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

China Uses Dual-Method Cyberattack on Czech Orgs

| 2026-06-02 19:50 CRITICAL LOW
Executive Summary AI-generated
China's complex relationship with the Czech Republic has been a source of tension between the two nations, particularly given their close economic ties and historical alliance. The country's government has long maintained strong support for Taiwan, while China has expressed concerns over its allyship to the island nation. This perceived imbalance in relations could explain why China is targeting specific organizations in the Czech Republic, including those involved in data exfiltration, with a focus on well-defined verticals such as government and public sector, research and academia, technology and software, and financial services.
Technical Mitigations AI-generated
* Implement secure email practices, such as verifying the authenticity of attachments and links before opening them. * Use anti-malware software that includes real-time protection and behavioral detection capabilities to detect and block suspicious activity. * Regularly update operating systems, applications, and firmware to ensure that known vulnerabilities are patched.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Dragon WeaveOperation Dragon Weave Tropic TrooperTropic Trooper
Target & Sectors
CENTRAL_ASIA CENTRAL_ASIA LATAM LATAM EUROPE EUROPE governmentgovernment technologytechnology
Incident Timeline
‎2026/05/26
China used a spear-phishing campaign targeting Czech organizations with an email containing a zip file and instructions to open it.
target_region Czechia
tactic Phishing
campaign Operation Dragon Weave
organisation Seqrite
organisation the Czech Social Security Administration
‎2026/06/02
China's cyberattack on the Czech Republic targets government and public sector organizations, using a dual-method approach that includes spear-phishing and conventional malware.
organisation APT
infrastructure Linux
organisation ESET
organisation PDF
organisation LNK
threat_actor Tropic Trooper
organisation DLL
data_breach 124 bytes
organisation Azureveil
organisation Rustcloak & Azureveil
organisation Microsoft Azure Blob Storage
organisation EDR
organisation XDR
organisation FIM
infrastructure 100 known machine names
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
data_breach
124
Bytes
Metrics
infrastructure
100
Known Machine Names
Intelligence Sources
Dark Reading 2026-06-02
Dark Reading 2026-06-02