Operation Dragon Weave Drops AdaptixC2 on Czech, Taiwanese Targets

Spear-phishing campaign hits government, academia, and finance with ZIP-borne lures and an open-source C2 framework.

ThreatVectr Newsdesk· 2 min read
Operation Dragon Weave Drops AdaptixC2 on Czech, Taiwanese Targets
Share

A spear-phishing campaign tracked as Operation Dragon Weave is delivering the AdaptixC2 post-exploitation agent to victims in the Czech Republic and Taiwan, according to research from Seqrite Labs.

The targeting is broad but deliberate. Government bodies, research institutions, universities, technology firms, and financial services have all turned up in the victim set. The pairing of Prague and Taipei (two capitals with active China-watching policy shops) is the part worth flagging for threat-intel teams.

Infection starts with a phishing email carrying a ZIP attachment. From there, the chain lands an AdaptixC2 agent on the host. AdaptixC2 is an open-source command-and-control framework that has been picked up by several intrusion sets over the past year as an alternative to Cobalt Strike and Sliver. It supports the usual menu: beaconing, lateral movement tooling, and modular post-ex tasking.

Seqrite has not publicly attributed the activity to a named group, though the victimology aligns with interests historically associated with China-nexus operators. (Treat that as circumstantial until someone publishes infrastructure overlap or code reuse.)

For defenders, a few things matter more than the codename.

First, ZIP attachments remain the carrier. Mail gateways that still pass through password-protected or double-extension archives to end users are doing the attackers' work for them. Block or detonate.

Second, AdaptixC2 traffic has documented detection opportunities. The framework's default profiles, JA3/JA4 fingerprints, and beacon cadence have been catalogued by several research teams since it went public. EDR and network sensors should be tuned for it specifically, not just "generic C2."

Third, the sector spread — government through finance — suggests the operators are casting wide and sorting hits afterward. Smaller research orgs and universities tend to be the soft entry point in these chains and should not assume they're below the threshold of interest.

No CVEs are in play here that have been disclosed publicly; this is a social-engineering and tooling story, not a vulnerability one. There is no patch to deploy. The mitigations are the ones already on your checklist: attachment policy, user reporting workflows that actually get triaged, and outbound network egress monitoring for unfamiliar C2 patterns.

If your organization has equities in Czech or Taiwanese policy, academic exchange, or supply-chain relationships with either, treat this as an active hunt prompt. Look for recent ZIP-delivered executables or LNKs in user download directories, unusual scheduled tasks, and beacon traffic to infrastructure flagged in the Seqrite writeup.

The AdaptixC2 project itself is not malicious — it is offensive security tooling. Its growing adoption by espionage actors is the trend line worth watching, and one defenders will likely see again before year-end.

© 2026 Threat Vectr