Also known as: UNC94
Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.(Citation: SentinelOne Aoqin Dragon June 2022)
Targeted Sectors
Executive Summary
Aoqin Dragon, also known as UNC94, is a suspected Chinese cyber espionage threat group that has been active since at least 2013, primarily targeting government, education, and telecommunication organizations in multiple countries. The group's motivations and goals are not well understood, but their activities suggest a focus on gathering sensitive information. Aoqin Dragon's tactics, techniques, and procedures (TTPs) are still being analyzed, but initial findings indicate a potential association with known malware and infrastructure.
Goals & Targeting
Aoqin Dragon's strategic objectives appear to be focused on gathering sensitive information from government, education, and telecommunication organizations in multiple countries. The group's targeting profile suggests a preference for organizations with access to valuable data, such as intellectual property, trade secrets, or sensitive government information. Typical victims of Aoqin Dragon's activities include government agencies, educational institutions, and telecommunication providers, all of which are likely to possess information of interest to the group.
Enhanced Description
Further analysis of Aoqin Dragon's activities reveals a sophisticated and coordinated approach to cyber espionage. The group's use of tailored malware and infrastructure suggests a high degree of planning and resources. Additionally, the group's ability to evade detection and persist in targeted networks for extended periods indicates a strong operational security posture. As more information becomes available, it is likely that Aoqin Dragon's TTPs will be further refined, providing a clearer understanding of the group's capabilities and intentions.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Aoqin Dragon's campaign patterns and operational tempo are not yet fully understood, but initial findings suggest a coordinated and targeted approach to cyber espionage. The group's activities appear to be focused on specific sectors and countries, with a preference for organizations with access to valuable data. Notable past operations include the targeting of government agencies, educational institutions, and telecommunication providers in Australia, Cambodia, Hong Kong, Singapore, and Vietnam.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on Aoqin Dragon is moderate, with some information gaps existing regarding the group's motivations, goals, and TTPs. Further analysis and research are needed to fully understand the group's capabilities and intentions.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
9
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
5
Tactics