{"id":664,"date":"2026-06-04T16:21:58","date_gmt":"2026-06-04T10:51:58","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=664"},"modified":"2026-08-18T16:25:00","modified_gmt":"2026-08-18T10:55:00","slug":"operation-dragon-weave-rustcloak-azureveil","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/","title":{"rendered":"Operation Dragon Weave Uses Rustcloak and Azureveil Against Czech and Taiwan Targets"},"content":{"rendered":"<p>Cybersecurity researchers have uncovered a sophisticated cyber espionage campaign known as Operation Dragon Weave, targeting organizations across the Czech Republic and Taiwan. The operation has been attributed to Chinese nation-state threat actors and demonstrates a combination of social engineering, cloud-native command-and-control techniques, and advanced malware delivery mechanisms.<\/p>\n<p>Organizations in government, public services, research institutions, academia, technology, software development, and financial services sectors have been identified as primary targets. The campaign highlights how modern threat actors continue to evolve their tactics to evade traditional security controls while maintaining long-term access to compromised environments.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tDetect Advanced Cyber Threats with Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How Operation Dragon Weave works<\/h2>\n<p>Attackers rely on a carefully structured, multi-stage infection chain that combines social engineering, malware delivery, and stealthy command-and-control techniques. The campaign is designed to maximize execution success while minimizing the chances of detection.<\/p>\n<h3>Spear-phishing serves as the initial entry point<\/h3>\n<p>The attack begins with carefully crafted spear-phishing emails designed to appear legitimate. Victims receive messages containing ZIP file attachments accompanied by believable themes such as business meeting invitations or appointments related to the Czech Social Security Administration.<\/p>\n<p>These lures increase the likelihood of user interaction and help attackers bypass initial suspicion.<\/p>\n<h3>Dual infection paths increase success rates<\/h3>\n<p>Once the ZIP archive is opened, victims are presented with multiple files that support two separate infection methods.<\/p>\n<h4>Path 1: Malicious LNK execution<\/h4>\n<p>One infection path relies on a malicious Windows shortcut (LNK) file. When opened, the shortcut launches PowerShell commands that decrypt and execute additional malicious components hidden within the archive.<\/p>\n<h4>Path 2: Rust-based dropper<\/h4>\n<p>The second path involves a self-contained executable that functions as a Rust-based dropper. This executable performs the malware deployment process directly without requiring additional user interaction.<\/p>\n<p>Although the delivery mechanisms differ, both infection paths ultimately converge on the same execution chain.<\/p>\n<h3>RuntimeBroker_update.exe launches the attack chain<\/h3>\n<p>Regardless of the initial entry method, the infection process eventually executes RuntimeBroker_update.exe, which loads a malicious DLL file. This DLL acts as a bridge for launching Rustcloak, the campaign&#8217;s Rust-based malware loader.<\/p>\n<h2>Rustcloak enables stealthy execution<\/h2>\n<p>Rustcloak plays a critical role in the operation by preparing the environment before deploying the final payload.<\/p>\n<p>One of its most notable capabilities is its extensive anti-analysis functionality. Researchers observed checks against more than 100 known sandbox environments and analyst machine names. If Rustcloak detects that it is running inside a security research environment, it can alter its behavior or terminate execution entirely.<\/p>\n<p>These anti-analysis techniques significantly reduce the chances of automated malware detection and reverse engineering.<\/p>\n<h2>Why Rust-based malware is gaining popularity<\/h2>\n<p>Threat actors increasingly favor Rust for malware development because it offers several advantages:<\/p>\n<ul>\n<li>Cross-platform compatibility<\/li>\n<li>Strong memory safety features<\/li>\n<li>Smaller detection footprint<\/li>\n<li>More complex reverse-engineering challenges<\/li>\n<li>Efficient performance with low resource consumption<\/li>\n<\/ul>\n<p>As Rust adoption grows among developers, security teams should expect to encounter more malware families built using the language.<\/p>\n<h2>Azureveil uses cloud infrastructure for command and control<\/h2>\n<p>After Rustcloak completes its execution phase, the final payload known as Azureveil is deployed.<\/p>\n<p>Azureveil is an Adaptix command-and-control (C2) agent designed to maintain communication with attacker-controlled infrastructure while minimizing detection opportunities.<\/p>\n<h3>Microsoft Azure Blob Storage acts as a dead-drop channel<\/h3>\n<p>Unlike traditional malware that communicates directly with attacker-owned servers, Azureveil leverages Microsoft Azure Blob Storage as a dead-drop channel.<\/p>\n<p>This approach allows malicious traffic to blend with legitimate cloud communications, making detection significantly more difficult for organizations that rely heavily on cloud services.<\/p>\n<h4>Azureveil can:<\/h4>\n<ul>\n<li>Retrieve attacker commands<\/li>\n<li>Execute instructions on compromised devices<\/li>\n<li>Upload encrypted beacon data<\/li>\n<li>Transfer command results<\/li>\n<li>Exfiltrate sensitive files<\/li>\n<\/ul>\n<p>Because communications occur through trusted cloud services, conventional network-based detection methods may struggle to identify malicious activity.<\/p>\n<h2>Why Operation Dragon Weave matters<\/h2>\n<p>Operation Dragon Weave demonstrates several trends commonly seen in modern China cyber espionage campaigns.<\/p>\n<p>Attackers are increasingly combining:<\/p>\n<ul>\n<li>Social engineering tactics<\/li>\n<li>Multi-stage malware delivery<\/li>\n<li>Anti-analysis mechanisms<\/li>\n<li>Cloud-hosted command-and-control infrastructure<\/li>\n<li>Stealthy data exfiltration techniques<\/li>\n<\/ul>\n<p>The campaign also serves as a reminder that a successful Taiwan cyberattack or government-focused espionage operation often begins with a single user interaction.<\/p>\n<p>Security teams should pay particular attention to:<\/p>\n<ul>\n<li>Unexpected LNK file execution<\/li>\n<li>Suspicious <a href=\"https:\/\/www.hexnode.com\/blogs\/the-beginners-guide-to-powershell-scripting\/\">PowerShell<\/a> activity<\/li>\n<li>DLL sideloading behavior<\/li>\n<li>Cloud storage communications from endpoints<\/li>\n<li>Unusual outbound data transfers<\/li>\n<li>Indicators of persistence and credential access<\/li>\n<\/ul>\n<h2>How Hexnode helps defend against advanced threats<\/h2>\n<p>Organizations facing sophisticated nation-state threats require strong visibility into endpoint activity, user actions, process behavior, and incident patterns.<\/p>\n<p>Since campaigns like Operation Dragon Weave often begin with user interaction and progress through multi-stage execution chains, security teams need enough endpoint context to understand what happened, how the threat moved forward, and which systems may be affected.<\/p>\n<h3>Detect suspicious execution chains with Hexnode XDR<\/h3>\n<p>Hexnode XDR can help security teams identify suspicious endpoint activity associated with advanced attack campaigns like Operation Dragon Weave. This includes unusual process behavior, script execution patterns, and anomalies surfaced through incident data.<\/p>\n<p>By analyzing process-level activity and correlating events within a device, Hexnode XDR enables security teams to investigate potential threats more effectively. This deeper endpoint context helps analysts understand how suspicious activity unfolds, validate incidents faster, and respond before threats escalate.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-Ultimate-Guide-to-XDR-Extended-Detection-and-Response.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>The Ultimate Guide to XDR<\/h4><p>Understand XDR essentials, architecture, benefits, and implementation for stronger threat detection.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\" aria-label=\"The Ultimate Guide to XDR\"><\/a><\/div><\/div><\/div>\n<h3>Strengthen endpoint security with Hexnode UEM<\/h3>\n<p>In addition to detection capabilities, <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> helps organizations reduce attack surface exposure through centralized endpoint management.<\/p>\n<p>Key capabilities include:<\/p>\n<ul>\n<li>Endpoint hardening policies<\/li>\n<li>Patch and update compliance<\/li>\n<li><a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-application-control\/\">Application control<\/a><\/li>\n<li>Script execution restrictions<\/li>\n<li>Security configuration enforcement<\/li>\n<\/ul>\n<p>These controls can help prevent malicious payloads from executing and limit attacker movement within the environment.<\/p>\n<h2>Conclusion<\/h2>\n<p>Operation Dragon Weave highlights the growing sophistication of modern cyber espionage operations. By combining spear-phishing, Rust-based malware, anti-analysis techniques, and cloud-hosted command-and-control infrastructure, attackers can increase stealth while reducing the likelihood of detection.<\/p>\n<p>Organizations should strengthen email security controls, improve endpoint visibility, and adopt cloud-aware detection strategies to defend against similar campaigns. As nation-state actors continue to evolve their techniques, proactive monitoring and rapid containment capabilities will remain essential components of enterprise security programs.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Start detecting advanced threats before they spread<\/h5><p>Try Hexnode XDR free for 14 days to stay ahead of emerging cyber threats and attacks.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why do threat actors increasingly use legitimate cloud services in attacks?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Using trusted cloud platforms helps attackers blend malicious traffic with normal business activity, making it harder for security tools and analysts to distinguish harmful communications from legitimate ones.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What role does threat hunting play in defending against advanced cyber campaigns?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Threat hunting helps security teams proactively search for suspicious behaviors that may not trigger traditional alerts, enabling earlier detection of sophisticated threats before significant damage occurs.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have uncovered a sophisticated cyber espionage campaign known as Operation Dragon Weave, targeting&#8230;<\/p>\n","protected":false},"author":6,"featured_media":665,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,19],"class_list":["post-664","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-cloud-and-saas","product_category-extended-detection-and-response","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Operation Dragon Weave Uses Rustcloak and Azureveil<\/title>\n<meta name=\"description\" content=\"Operation Dragon Weave targets Czech and Taiwan organizations using Rustcloak, Azureveil, and Azure-based command-and-control tactics\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Operation Dragon Weave Uses Rustcloak and Azureveil\" \/>\n<meta property=\"og:description\" content=\"Operation Dragon Weave targets Czech and Taiwan organizations using Rustcloak, Azureveil, and Azure-based command-and-control tactics\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-04T10:51:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T10:55:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Operation Dragon Weave Uses Rustcloak and Azureveil Against Czech and Taiwan Targets\",\"datePublished\":\"2026-06-04T10:51:58+00:00\",\"dateModified\":\"2026-08-18T10:55:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/\"},\"wordCount\":1115,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp\",\"articleSection\":[\"Phishing\",\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/\",\"name\":\"Operation Dragon Weave Uses Rustcloak and Azureveil\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp\",\"datePublished\":\"2026-06-04T10:51:58+00:00\",\"dateModified\":\"2026-08-18T10:55:00+00:00\",\"description\":\"Operation Dragon Weave targets Czech and Taiwan organizations using Rustcloak, Azureveil, and Azure-based command-and-control tactics\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Operation Dragon Weave Uses Rustcloak and Azureveil Against Czech and Taiwan Targets\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/operation-dragon-weave-rustcloak-azureveil\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Operation Dragon Weave Uses Rustcloak and Azureveil Against Czech and Taiwan Targets\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Operation Dragon Weave Uses Rustcloak and Azureveil","description":"Operation Dragon Weave targets Czech and Taiwan organizations using Rustcloak, Azureveil, and Azure-based command-and-control tactics","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/","og_locale":"en_US","og_type":"article","og_title":"Operation Dragon Weave Uses Rustcloak and Azureveil","og_description":"Operation Dragon Weave targets Czech and Taiwan organizations using Rustcloak, Azureveil, and Azure-based command-and-control tactics","og_url":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-04T10:51:58+00:00","article_modified_time":"2026-08-18T10:55:00+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Operation Dragon Weave Uses Rustcloak and Azureveil Against Czech and Taiwan Targets","datePublished":"2026-06-04T10:51:58+00:00","dateModified":"2026-08-18T10:55:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/"},"wordCount":1115,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp","articleSection":["Phishing","Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/","url":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/","name":"Operation Dragon Weave Uses Rustcloak and Azureveil","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp","datePublished":"2026-06-04T10:51:58+00:00","dateModified":"2026-08-18T10:55:00+00:00","description":"Operation Dragon Weave targets Czech and Taiwan organizations using Rustcloak, Azureveil, and Azure-based command-and-control tactics","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Operation-Dragon-Weave-Uses-Rustcloak-and-Azureveil-Against-Czech-and-Taiwan-Targets.png?format=webp","width":1340,"height":700,"caption":"Operation Dragon Weave Uses Rustcloak and Azureveil Against Czech and Taiwan Targets"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/operation-dragon-weave-rustcloak-azureveil\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Operation Dragon Weave Uses Rustcloak and Azureveil Against Czech and Taiwan Targets"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=664"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/664\/revisions"}],"predecessor-version":[{"id":666,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/664\/revisions\/666"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/665"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}