Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Mongall

Mongall

TLP:CLEAR
Family

AI Analysis

· 12 hours ago

Executive Summary

Mongall is a Windows backdoor that provides persistent remote control, allowing adversaries to execute commands, move laterally, and exfiltrate information. Linked to Aoqin Dragon, it remains an active tool in the cyber‑crime landscape with modular capabilities for stealth and persistence.

Enhanced Description

Mongall is a Windows‑only backdoor that has been detected in the wild since at least 2013 and has been linked to the Aoqin Dragon threat activity observed by SentinelOne in June 2022. The tool establishes persistent command‑and‑control (C&C) channels, often over HTTP/HTTPS or custom protocols, enabling an adversary to remotely execute commands, download additional payloads, exfiltrate data, and manipulate victim systems. Once installed Mongall employs multiple methods for persistence, including modifying the Windows registry run keys and creating scheduled tasks. It also uses process injection and stealth techniques that reduce its footprint within standard defensive tooling. The backdoor supports a modular architecture; adversaries can push additional modules such as keyloggers or credential harvesters, allowing lateral movement and data extraction from compromised hosts. The malware’s activity aligns with typical state‑sponsored or advanced threat actor behaviors: use of PowerShell for execution, encrypted C&C traffic to avoid detection, and a focus on stealthy persistence. Its continued presence in recent Aoqin Dragon campaigns suggests it remains actively maintained and tailored by attackers for diverse infrastructures. In summary, Mongall represents a sophisticated backdoor platform capable of delivering command‑and‑control capabilities, persistence, data exfiltration, and modular expansion to meet strategic objectives of threat actors.

Key Capabilities

  • Persistent execution via registry run keys and scheduled tasks
  • Remote command execution over HTTP/HTTPS or custom C&C protocols
  • Modular architecture for adding functionality such as keylogging or credential theft
  • Stealth through process injection, encrypted communication, and obfuscation
  • Data exfiltration using standard and non‑standard ports
  • Potential lateral movement across networked Windows machines

ATT&CK Techniques

T1059
T1086
T1071
T1060
T1547
T1003

Recommended Actions

  • Implement detection rules for unknown processes named ‘mongall’ or variations in the SYSTEM directory
  • Block outbound connections to known C&C IPs or domains identified by SentinelOne research
  • Monitor for anomalous PowerShell activity, such as obfuscated scripts or encoded command strings
  • Maintain updated host‑based intrusion detection and endpoint protection capable of detecting registry run key additions and scheduled task creation
  • Employ network segmentation and strict egress filtering to limit unauthorized traffic
  • Conduct thorough forensic analysis on compromised hosts for signs of modular payloads and credential dumping

Suggested Tags

Backdoor
C2
Windows
Persistence
Modular
Aoqin Dragon
State-sponsored
Advanced Persistent Threat

Confidence Assessment

Confidence in the core facts about Mongall (Windows backdoor, persistence via registry/run keys, association with Aoqin Dragon) is medium based on SentinelOne statements. Detailed information on payload variants, exact C&C infrastructure, and full behavioral profile remains limited due to paucity of open samples; further analysis would improve understanding of its capabilities and defensive posture.

Description

Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.(Citation: SentinelOne Aoqin Dragon June 2022)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.