A newly observed cyber espionage campaign, dubbed “Autumn Dragon,” is targeting government and media organizations across Southeast Asia.
Researchers linked the campaign to a China-nexus threat actor active since early 2025, using a sophisticated chain of DLL sideloading attacks to compromise networks in Laos, Cambodia, Singapore, the Philippines, and Indonesia.
According to security analysts, the attackers rely heavily on social engineering combined with known vulnerabilities to deliver multi-stage malware implants.
The campaign’s first stage begins with a spearphishing email carrying a malicious RAR archive titled “Proposal_for_Cooperation_3415.05092025.rar,” exploiting CVE-2025-8088, a path traversal flaw in WinRAR.
When opened, the archive drops a batch file named “Windows Defender Definition Update.cmd,” which automatically downloads the next payload from Dropbox and establishes persistence via the Windows Startup folder and registry Run keys.
Multi-Stage Compromise via DLL Sideloading
The second stage introduces a backdoor leveraging DLL sideloading in legitimate software to avoid detection. The dropper executes a genuine OBS Browser executable that loads a tampered “libcef.dll” containing malicious code.
This backdoor communicates with the attacker’s Telegram bot, receiving commands such as executing shell commands, capturing screenshots, or uploading new payloads. Using Telegram as its command-and-control (C2) channel helps the attacker blend into regular network traffic.
In subsequent stages, the malware continues to use DLL sideloading with legitimate binaries, such as Adobe’s Creative Cloud Helper and OperaGX executables, to deploy follow-on payloads stealthily.
The third-stage loader (CRClient.dll) decrypts and runs an encrypted file, “Update.lib,” which serves as the trigger for the final implant.
The final backdoor communicates with its C2 infrastructure over HTTPS, using XOR encryption to conceal traffic, and uses domains like public.megadatacloud.com and IP address 104.234.37.45.
The fourth-stage implant grants attackers complete control over compromised systems, enabling command execution, data theft, and the deployment of additional malware. It supports commands identified by unique IDs, allowing remote shell access, file manipulation, and DLL execution.
Targeting Southeast Asia and Attribution
Victims are mainly located in countries bordering the South China Sea, such as Indonesia, Singapore, and the Philippines, with a focus on government and media institutions.
Evidence points to an advanced Chinese threat actor with ties to past APT41 activity, though attribution remains of medium confidence. The attackers employ region-specific geofencing and custom user-agent checks to restrict payload access and evade detection.
Researchers have published Yara signatures and indicators of compromise to aid defenders in detection. The “Autumn Dragon” campaign highlights the continued use of trusted-application abuse and multi-stage DLL sideloading to conduct stealthy espionage against key sectors in Southeast Asia.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates