Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DragonOK

Also known as: DragonOK, Moafee, BRONZE OVERBROOK, G0017, G0002, Shallow Taurus, HelloBridge, the threat actor, tracked as

Description

**Targets:** Japan **Toolset/Malware:** CVE-2015-1641, Sysget, IsSpace, Rambo Backdoor

Goals & Targeting

Targeted Sectors

Telecommunications
Manufacturing
Government
Defense
Critical infrastructure
Financial services
Media
Aerospace

Targeted Countries / Regions

JP
TW
RU
KR
IR
CN
US

AI Analysis

· 1 week ago

Executive Summary

DragonOK, also known as Moafee, BRONZE OVERBROOK, G0017, G0002, and Shallow Taurus, is a nation-state threat actor primarily targeting Japan. The group is suspected to engage in espionage activities, leveraging a combination of known malware and exploits to achieve its objectives. DragonOK has been linked to tools like Sysget, IsSpace, Rambo Backdoor, PlugX, and PoisonIvy, indicating a focus on maintaining long-term access and persistence within targeted networks.

Goals & Targeting

DragonOK's strategic objectives appear to center around espionage, likely aimed at gathering intelligence from Japanese institutions. The group's sustained targeting of Japan suggests a deep interest in the country's policies, military, or economic activities. Typical victims include government agencies, defense contractors, and other entities that may possess sensitive information. DragonOK's focus on long-term access tools like backdoors indicates a patient and methodical approach to exfiltrating data over extended periods.

Enhanced Description

DragonOK is a sophisticated nation-state actor with a primary focus on espionage activities. The group has demonstrated a consistent interest in targeting Japanese organizations, likely aiming to gather sensitive political, economic, or military information. DragonOK's operational toolkit includes several malware families such as Sysget, IsSpace, and Rambo Backdoor, which suggest an emphasis on backdoor creation and persistence within targeted systems. Additionally, the group has been associated with PlugX and PoisonIvy, indicating a potential reliance on known tools for lateral movement and data exfiltration. DragonOK's targeting strategy appears to focus on sectors critical to Japan's national interests, such as government, defense, and possibly others involved in sensitive technological research.

Key Capabilities

  • Developing and deploying custom malware for persistence and backdoor creation
  • Leveraging known exploits (e.g., CVE-2015-1641)
  • Using established tools like PlugX and PoisonIvy for lateral movement and control
  • Spear-phishing campaigns to compromise targets
  • Maintaining long-term access through persistence mechanisms

MITRE ATT&CK Tactics

Persistence
Lateral Movement
Credential Access
Exfiltration
Defense Evasion

ATT&CK Techniques

T1059.003
T1077.001
T1566.002
T1078
T1133

Software / Tooling

Sysget
IsSpace
Rambo Backdoor
PlugX
PoisonIvy

Campaigns & Victims

DragonOK's campaign patterns suggest a focus on maintaining persistent access within targeted networks, possibly over extended periods. The group has shown an interest in Japanese entities, with activity potentially linked to espionage efforts. Specific campaigns remain unclear, but the combination of tools and techniques suggests an APT-like approach, targeting high-value assets for intelligence collection.

IOC Patterns

  • Use of known exploits (e.g., CVE-2015-1641)
  • Deployment of custom backdoors like Sysget and IsSpace
  • Lateral movement using PlugX and PoisonIvy
  • Registry modifications for persistence
  • Scheduled task creation for long-term access

Recommended Actions

  • Implement strict monitoring of known DragonOK TTPs, particularly around exploit usage and backdoor activity.
  • Review network logs for signs of lateral movement or data exfiltration attempts.
  • Patch systems against known vulnerabilities like CVE-2015-1641
  • Monitor for the creation of new registry entries or scheduled tasks that may indicate persistence mechanisms.
  • Conduct regular training for employees on identifying and reporting potential phishing attempts.

Suggested Tags

APT
nation-state
espionage
Japan

Confidence Assessment

Confidence in DragonOK's attributes is moderate to high, with clear links to known tools and espionage motives. However, specific campaign details and exact TTPs remain unclear due to limited公开 reporting on the group. Further analysis of IOC patterns and tool usage would enhance understanding.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 5 Domain 14 Filename 1

References

  1. Operation Quantum Entanglement — Haq, T., Moran, N., Vashisht, S., Scott, M. (2014, September). OPERATION QUANTUM ENTANGLEMENT. Retrieved November 17, 2024.
  2. New DragonOK — Miller-Osborn, J., Grunzweig, J.. (2015, April). Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese Targets. Retrieved November 4, 2015.
  3. apt.etda.or.th — Cited by web research for: HelloBridge
  4. docs.rapid7.com — Cited by web research for: T1583
  5. attack.mitre.org — Cited by web research for: T1027
  6. unit42.paloaltonetworks.com — Cited by web research for: PowerShell
  7. attack.mitre.org — Cited by web research for: Windows Command Shell
  8. unit42.paloaltonetworks.com — Cited by web research for: XCSSET

Intel Summary

11

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

APT
nation-state
espionage
Japan

Details

MITRE ID
G0017
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
Jul 21, 2026
STIX ID
intrusion-set--f3bdec95-3d62-42d9-a840-29630f6cdc1a
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.