Actor Profile
Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republic and Taiwan. The targeting pattern suggests strategic interest in political, technological, and financial intelligence from entities in these regions. The operation demonstrates coordination and sector-specific targeting consistent with state-sponsored espionage objectives.
TTPs (Tactics, Techniques, Procedures)
The campaign employs spear-phishing emails as the initial access vector (T1566.001 - Spearphishing Attachment), delivering malicious ZIP archives containing the AdaptixC2 malware agent. This approach reflects classic APT tradecraft for targeted intrusion operations. The use of a custom C2 framework (AdaptixC2) indicates investment in bespoke tooling for command and control (T1071 - Application Layer Protocol). The multi-sector targeting across government, research, academic, technology, and financial services demonstrates broad intelligence collection requirements typical of nation-state operations.
Targets & Patterns
The campaign targets officials and citizens in the Czech Republic and Taiwan, with focus on five key sectors: government, research institutions, academic organizations, technology companies, and financial services. The geographic focus on Taiwan aligns with long-standing Chinese intelligence priorities regarding cross-strait relations and technology transfer. Czech Republic targeting may reflect interest in European Union policy positions, NATO activities, or advanced research and technology sectors. The breadth of targeted sectors suggests comprehensive intelligence gathering rather than narrow operational focus, consistent with strategic espionage campaigns.
Historical Context
China-aligned APT groups have historically conducted sustained espionage campaigns against Taiwan across multiple threat clusters (APT1, APT10, APT40, Mustang Panda, among others), making this geographic focus consistent with established patterns. Czech Republic targeting represents part of broader Chinese intelligence operations against European entities, particularly those involved in sensitive technology, 5G infrastructure debates, and geopolitical positioning. The use of custom malware frameworks like AdaptixC2 follows the trend of China-nexus actors developing proprietary toolsets alongside use of publicly available tools.
Defensive Recommendations
- Implement robust email security controls to detect and quarantine spear-phishing attempts with ZIP attachments, particularly from external senders targeting high-value personnel (T1566.001)
- Deploy endpoint detection rules to identify suspicious execution chains from archive files, including monitoring for unusual parent-child process relationships following ZIP extraction
- Establish network monitoring for AdaptixC2 C2 traffic patterns, including anomalous outbound connections from workstations in targeted sectors (T1071)
- Conduct targeted security awareness training for government, research, academic, technology, and financial services personnel on China-aligned spear-phishing tactics and social engineering techniques
- Implement application whitelisting and restrict execution of unsigned binaries from user-writable directories to prevent malware deployment from phishing vectors
---
# Geopolitical Context
Geopolitical Context
Operation Dragon Weave represents a dual-track espionage effort consistent with Beijing's strategic priorities in Central Europe and the Indo-Pacific. The Czech Republic has emerged as a vocal critic of Chinese technology and human rights policies within the EU, particularly regarding 5G infrastructure and Taiwan relations. Taiwan remains a core focus of Chinese intelligence collection given cross-strait tensions. The simultaneous targeting of both countries suggests coordinated intelligence requirements spanning European political dynamics and Taiwan's technological and governmental sectors. The breadth of targeted sectors—government, research, academic, technology, and financial services—indicates comprehensive strategic intelligence gathering rather than narrow tactical objectives.
State Actor Alignment
The campaign is attributed to China-aligned groups, though specific attribution to state organs has not been publicly detailed. The targeting pattern aligns with known priorities of Chinese intelligence services, particularly the Ministry of State Security (MSS). Both the Czech Republic and Taiwan maintain formal cybersecurity cooperation with Western partners, and this activity may inform future sanctions discussions or technology export controls within the EU and among Indo-Pacific allies. The Czech National Cyber and Information Security Agency (NÚKIB) has previously issued warnings regarding Chinese state-linked cyber threats.
Business Impacty pro region
For Europe, this campaign underscores the targeting of smaller EU member states that have adopted critical stances on China policy, potentially as leverage or early warning indicators of shifting political positions. The Czech Republic's experience may inform broader EU cyber resilience strategies and intelligence-sharing protocols. In the Indo-Pacific, the Taiwan dimension reinforces persistent Chinese cyber operations against the island's critical sectors amid heightened military and diplomatic pressure. The cross-regional nature of the campaign may prompt closer coordination between European and Indo-Pacific cybersecurity frameworks, including through mechanisms like the EU-Taiwan digital dialogue and NATO-partner information exchanges.
Forecast
If the campaign continues unmitigated, affected organizations in both countries are likely to face sustained espionage pressure, particularly around policy formulation and technology development. Should Czech or Taiwanese authorities publicly attribute the activity with high confidence, diplomatic responses may include formal protests, potential EU-level discussions on countermeasures, and enhanced cybersecurity cooperation between Prague and Taipei. If the AdaptixC2 toolset is further analyzed and shared among Western intelligence partners, detection and disruption capabilities may improve across allied networks within the next quarter. Escalation in cross-strait tensions or Czech participation in Taiwan-related diplomatic initiatives could correlate with intensified targeting.
