TAIPEI (Taiwan News) — A suspected China-linked cyber campaign used fake government-style files to try to breach targets in Taiwan and the Czech Republic, cybersecurity company Seqrite said in a recent report.
Seqrite published its findings on May 29, days before Czech Senate President Milos Vystrcil began a Taiwan visit, per CNA.
The campaign, named Operation Dragon Weave, sent spearphishing emails with ZIP attachments to people in government, tech, finance, research, and academic circles. Opening the files triggered a multi-step infection process that could run malware in the background, steal data, and allow remote access to compromised computers, according to CNA.
Rather than rely on generic lures, the attackers tailored file names to local targets. The Taiwan version used traditional Chinese and posed as a notice for the results of a project application review, while the Czech version mimicked a social security appointment notice.
Seqrite researcher Priya Patel said the extracted archive presented victims with files that appeared legitimate, but were actually arranged to deliver malicious payloads, per CNA. For example, the Czech-language files included a specific name and appointment details.
Seqrite described the activity as cyberespionage and said the files closely imitated official communications. The India-based company tracks malware, viruses, advanced persistent threats, and nation-state cyberattacks.




