CNChinaconfidence: 50G0002G0017

DragonOKDragonOK

Also known as: Moafee · BRONZE OVERBROOK · G0017 · G0002 · Shallow Taurus · DragonOK

Origin
CN
Known aliases
6
Target sectors
1
Attribution
State-sponsored

Profile

Threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. 2223 It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.

Aliases· 6

MoafeeBRONZE OVERBROOKShallow TaurusDragonOK
G0017G0002

Target sectors· 1

Private sector

Known victims· 1

  • United States

MITRE ATT&CK Group crosswalk

G0002G0017

References

  1. https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-operation-quantum-entanglement.pdf
  2. https://attack.mitre.org/wiki/Groups
  3. https://www.forcepoint.com/de/blog/x-labs/trojanized-adobe-installer-used-install-dragonok-s-new-custom-backdoor
  4. https://github.com/m0n0ph1/APT_CyberCriminal_Campagin_Collections-1/blob/master/2017/2017.02.15.deep-dive-dragonok-rambo-backdoor/Deep%20Dive%20on%20the%20DragonOK%20Rambo%20Backdoor%20_%20Morphick%20Cyber%20Security.pdf
  5. https://www.cfr.org/interactive/cyber-operations/moafee
  6. https://unit42.paloaltonetworks.com/unit-42-identifies-new-dragonok-backdoor-malware-deployed-against-japanese-targets/
  7. https://unit42.paloaltonetworks.com/unit42-dragonok-updates-toolset-targets-multiple-geographic-regions/
  8. https://www.phnompenhpost.com/national/kingdom-targeted-new-malware

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
DragonBreath
Group
Moafee
Actor
DragonSpark
Actor
DragonRank
Actor
DAGGER PANDA
Actor
Aoqin Dragon
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.