From phishing to Google Drive C2: Silver Dragon expands APT41 playbook

2026-03-04T21:45:31Z7faf79140439d86d8dae7860bfdc1fbe3173d6e1fbb1ced33551a43b152ba038
CVE-2026-0628CVE-2026-21385APT41Ariomex data leakCISA KEVCobalt StrikeFacebook outageGoogle Drive C2Iranian threatsMadison Square GardenOAuth redirectionOracle E-Business SuiteSilver DragonUK NCSCUniversity of Hawaiʻi Cancer Centerdata breachexploited vulnerabilityphishingransomware

What happened

Feed of security news (Mar 2–4, 2026) reporting multiple active threats and large breaches: Check Point describes “Silver Dragon” (linked to APT41) targeting governments via server exploits and phishing, using Cobalt Strike and Google Drive as C2; Microsoft warns of OAuth redirection phishing campaigns against government users; Google/Palo Alto report actively exploited flaws (Qualcomm Android CVE-2026-21385 confirmed exploited; Chrome extension/ Gemini Live hijack via CVE-2026-0628); CISA added multiple flaws (including Qualcomm and Broadcom/VMware Aria Operations) to its Known Exploited-Vuln

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
7faf79140439d86d8dae7860bfdc1fbe3173d6e1fbb1ced33551a43b152ba038
Enrichment time
2026-03-04T21:45:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · From phishing to Google Drive C2: Silver Dragon expands APT41 playbook · Baitaphish