Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Night Dragon

Also known as: Night Dragon, G0014

Description

**Targets:** A threat actor compromised U.S. oil companies through spear phishing and remote administration tools. Oil, Energy and Petrochemical (OpNightDragon)

TTP Summary

Night Dragon

Goals & Targeting

Targeted Sectors

Energy

Targeted Countries / Regions

US

AI Analysis

· 1 week ago

Executive Summary

Night Dragon is a nation-state threat actor primarily involved in espionage activities targeting the energy sector, particularly in the United States. The group has demonstrated advanced capabilities in compromising oil and energy companies through spear phishing and remote administration tools, aiming to gather sensitive information.

Goals & Targeting

Night Dragon's primary goal is espionage, targeting the energy sector in the United States. This suggests a focus on gathering sensitive information related to energy production, infrastructure, and possibly geopolitical strategies. The actor likely seeks to acquire intelligence that could impact national security or provide strategic advantages to their sponsoring nation.

Enhanced Description

Night Dragon, also known as G0014, is a sophisticated nation-state actor focused on espionage within the energy sector. The group has been observed targeting U.S. oil companies through spear phishing campaigns and deploying custom remote administration tools to gain unauthorized access to critical systems. These activities are part of broader efforts to extract sensitive information related to energy operations, likely for strategic or military advantage. The threat actor's operational persistence and use of tailored attack vectors highlight their capability to adapt to defensive measures, making them a significant concern for energy sector organizations.

Key Capabilities

  • Spear phishing attacks using Office documents
  • Remotely controlled backdoors for persistence
  • Abuse of legitimate remote administration tools
  • DLL injection techniques to maintain persistence

MITRE ATT&CK Tactics

Collection
Exfiltration
Defense-Evasion

ATT&CK Techniques

T1078
T1055.002

Software / Tooling

Custom remote administration software with backdoor capabilities
Malicious Office documents with embedded macros

Campaigns & Victims

Night Dragon's campaigns have focused on compromising energy sector organizations through targeted phishing and malware deployment. The actor has demonstrated patience and operational discipline, likely leveraging long-term access to exfiltrate data over extended periods. Their focus on the U.S. energy sector indicates a strategic interest in critical infrastructure, with potential ties to nation-state interests.

IOC Patterns

  • Spear-phishing emails targeting energy sector employees
  • Malicious Office documents with embedded macros
  • Remote administration tool backdoors with persistence mechanisms

Recommended Actions

  • Implement advanced email filtering and phishing detection solutions.
  • Conduct regular training on identifying spear phishing attempts.
  • Monitor network traffic for signs of remote command-and-control activity.
  • Use endpoint detection and response (EDR) tools to identify potential backdoor activities.
  • Patch and secure remote administration tools from known vulnerabilities.

Suggested Tags

Nation-state
APT
Espionage
Energy sector

Confidence Assessment

There is moderate confidence in the characterization of Night Dragon as a nation-state actor involved in espionage against the energy sector. The group's activities are well-documented, but some details about their specific tools and tactics remain unclear. Additional visibility into their attack techniques and the scope of their operations would enhance the understanding of this threat.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Phishing
Nation-state
Espionage
Energy sector

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.