Also known as: DragonOK, Moafee, BRONZE OVERBROOK, G0017, G0002, Shallow Taurus, HelloBridge, the threat actor, tracked as
**Targets:** Japan **Toolset/Malware:** CVE-2015-1641, Sysget, IsSpace, Rambo Backdoor
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DragonOK, also known as Moafee, BRONZE OVERBROOK, G0017, G0002, and Shallow Taurus, is a nation-state threat actor primarily targeting Japan. The group is suspected to engage in espionage activities, leveraging a combination of known malware and exploits to achieve its objectives. DragonOK has been linked to tools like Sysget, IsSpace, Rambo Backdoor, PlugX, and PoisonIvy, indicating a focus on maintaining long-term access and persistence within targeted networks.
Goals & Targeting
DragonOK's strategic objectives appear to center around espionage, likely aimed at gathering intelligence from Japanese institutions. The group's sustained targeting of Japan suggests a deep interest in the country's policies, military, or economic activities. Typical victims include government agencies, defense contractors, and other entities that may possess sensitive information. DragonOK's focus on long-term access tools like backdoors indicates a patient and methodical approach to exfiltrating data over extended periods.
Enhanced Description
DragonOK is a sophisticated nation-state actor with a primary focus on espionage activities. The group has demonstrated a consistent interest in targeting Japanese organizations, likely aiming to gather sensitive political, economic, or military information. DragonOK's operational toolkit includes several malware families such as Sysget, IsSpace, and Rambo Backdoor, which suggest an emphasis on backdoor creation and persistence within targeted systems. Additionally, the group has been associated with PlugX and PoisonIvy, indicating a potential reliance on known tools for lateral movement and data exfiltration. DragonOK's targeting strategy appears to focus on sectors critical to Japan's national interests, such as government, defense, and possibly others involved in sensitive technological research.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DragonOK's campaign patterns suggest a focus on maintaining persistent access within targeted networks, possibly over extended periods. The group has shown an interest in Japanese entities, with activity potentially linked to espionage efforts. Specific campaigns remain unclear, but the combination of tools and techniques suggests an APT-like approach, targeting high-value assets for intelligence collection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in DragonOK's attributes is moderate to high, with clear links to known tools and espionage motives. However, specific campaign details and exact TTPs remain unclear due to limited公开 reporting on the group. Further analysis of IOC patterns and tool usage would enhance understanding.
No campaigns linked yet.
No observed data linked yet.
11
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics