Also known as: WEBJACK, STAC6451 was published, CL-STA-0048, Thallium, Black Banshee, Mythic Leopard, Transparent Tribe
DragonRank operates primarily against public‑facing web services in Asia and Europe, targeting organizations ranging from government to consumer retail. The group’s core technique is the deployment of malicious IIS modules—most notably BadIIS—which hijack search‑engine requests and deliver black‑hat traffic to third‑party sites. After compromising a server they install a portfolio of backdoors, including the PlugX RAT for remote control and credential dumping via Mimikatz and its derivatives. The actor also leverages publicly known application vulnerabilities (CVE‑2024‑9047 on IIS, WordPress file‑upload flaws) to drop .aspx web shells such as ASPXSpy or customized PowerShell stagers. These shells enable in‑memory execution of encoded payloads, DLL sideloading via legitimate binaries (AppLaunch.exe, certutil), and reflective code loading for evasion. DragonRank’s operations are tightly scripted: scheduled tasks, RDP manipulation through registry edits, and HTTPS/WS C2 tunnels using custom modules or standard frameworks such as Cobalt Strike. They further employ DNS exfiltration and hex‑staging via certutil to hide data outflows. Overall the group presents a hybrid of cyber‑crime economics—SEO fraud and credential theft—with a sophistication that reflects organized threat‑intelligence communities. The actor’s persistence is compounded by lateral movement through remote desktop, WMI, and copy‑of‑domain accounts (e.g., sysadmin123). By maintaining a foothold in compromised networks it can exfiltrate large amounts of data or pivot to other critical assets such as financial or telecommunication systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DragonRank is a financially motivated, Chinese‑speaking threat actor that exploits legacy IIS, phpMyAdmin and WordPress to install malicious web shells and the BadIIS module. Using SEO poisoning they redirect search‑engine crawlers and end users to fraudulent sites while leveraging PlugX for lateral movement, persistence and credential theft.
Goals & Targeting
DragonRank appears primarily driven by monetization: SEO poisoning generates click‑through revenue for fraudulent gambling, e‑commerce and phishing sites; credential dumping fuels identity theft for future scams. Their target list spans a broad spectrum—government, finance, telecom, healthcare, education—suggesting opportunistic threat‑crowd rather than purely espionage. The focus on legacy IIS infrastructure indicates both low technical barriers and high potential exposure. The group also appears to be expanding its C2 surface, using cloud services and DNS tunneling, likely to sustain long‑term operations. Strategically, the actor blends short‑cycle web shell attacks with longer‑term RAT deployments (PlugX) enabling data exfiltration and privilege escalation. This hybrid approach aligns with financial‐gain objectives while providing a secondary profit stream from credential sales or ransomware deployments. Key capabilities include: - SEO poisoning via injected IIS modules (BadIIS) - Public‑app exploitation: IIS, phpMyAdmin, WordPress - Web‑shell deployment (ASPXSpy, PowerShell stagers) - PlugX RAT installation for persistence and lateral movement - Credential dumping with Mimikatz/BadPotato variants - DLL sideloading & reflective code loading for evasion - Scheduled tasks and RDP registry changes for persistence - Hex staging and certutil downloads for payload delivery - DNS exfiltration using subdomain enumeration - C2 over HTTP/HTTPS/WebSockets and custom IIS modules
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DragonRank’s campaigns have a documented operational tempo of weeks to months, often following the lifecycle of an exploited server: initial exploitation via public‑facing application vulnerabilities, web shell deployment, SEO poisoning launch, and subsequent lateral movement before data exfiltration or monetization. Victims cover multiple industries—government, finance, telecom, healthcare and media—across countries such as China, India, Vietnam, Ukraine and the United States, reflecting an opportunistic but geographically wide reach. Notable past operations include the “Rewrite” campaign documented by Palo Alto Networks (Targeting European IIS servers), the “WEBJACK” series that hijacked legacy Windows servers for gambling fraud sites, and the recently reported “GhostRedirector” attack which added a malicious IIS module to inject fake content. Each operation typically leveraged the same core kit—BadIIS for SEO poisoning and PlugX for persistence. The group's pattern of rapidly adding new C2 domains, shifting between HTTP, HTTPS, WebSocket, and DNS tunneling indicates an evolving infrastructure aimed at evading detection while retaining flexibility across varied victim environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a solid picture of DragonRank’s technical capabilities, campaign patterns and monetization motives, with a moderate to high confidence level. Attribution remains uncertain due to the lack of clear nation‑state indicators beyond language; however the structured TTPs and toolset strongly support a financially motivated cyber‑crime organization. Gaps remain around exact operational timelines (first/last seen), full scope of victim industries across all regions, and whether DragonRank is evolving into a more advanced threat actor with espionage objectives.
No campaigns linked yet.
No observed data linked yet.
44
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics