Executive Summary
Mongall is a Windows backdoor that provides persistent remote control, allowing adversaries to execute commands, move laterally, and exfiltrate information. Linked to Aoqin Dragon, it remains an active tool in the cyber‑crime landscape with modular capabilities for stealth and persistence.
Enhanced Description
Mongall is a Windows‑only backdoor that has been detected in the wild since at least 2013 and has been linked to the Aoqin Dragon threat activity observed by SentinelOne in June 2022. The tool establishes persistent command‑and‑control (C&C) channels, often over HTTP/HTTPS or custom protocols, enabling an adversary to remotely execute commands, download additional payloads, exfiltrate data, and manipulate victim systems. Once installed Mongall employs multiple methods for persistence, including modifying the Windows registry run keys and creating scheduled tasks. It also uses process injection and stealth techniques that reduce its footprint within standard defensive tooling. The backdoor supports a modular architecture; adversaries can push additional modules such as keyloggers or credential harvesters, allowing lateral movement and data extraction from compromised hosts. The malware’s activity aligns with typical state‑sponsored or advanced threat actor behaviors: use of PowerShell for execution, encrypted C&C traffic to avoid detection, and a focus on stealthy persistence. Its continued presence in recent Aoqin Dragon campaigns suggests it remains actively maintained and tailored by attackers for diverse infrastructures. In summary, Mongall represents a sophisticated backdoor platform capable of delivering command‑and‑control capabilities, persistence, data exfiltration, and modular expansion to meet strategic objectives of threat actors.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core facts about Mongall (Windows backdoor, persistence via registry/run keys, association with Aoqin Dragon) is medium based on SentinelOne statements. Detailed information on payload variants, exact C&C infrastructure, and full behavioral profile remains limited due to paucity of open samples; further analysis would improve understanding of its capabilities and defensive posture.
Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.(Citation: SentinelOne Aoqin Dragon June 2022)