Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Aoqin Dragon

Also known as: UNC94

Description

Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.(Citation: SentinelOne Aoqin Dragon June 2022)

Goals & Targeting

Targeted Sectors

Government
Education
Telecommunications

AI Analysis

· 2 weeks ago

Executive Summary

Aoqin Dragon, also known as UNC94, is a suspected Chinese cyber espionage threat group that has been active since at least 2013, primarily targeting government, education, and telecommunication organizations in multiple countries. The group's motivations and goals are not well understood, but their activities suggest a focus on gathering sensitive information. Aoqin Dragon's tactics, techniques, and procedures (TTPs) are still being analyzed, but initial findings indicate a potential association with known malware and infrastructure.

Goals & Targeting

Aoqin Dragon's strategic objectives appear to be focused on gathering sensitive information from government, education, and telecommunication organizations in multiple countries. The group's targeting profile suggests a preference for organizations with access to valuable data, such as intellectual property, trade secrets, or sensitive government information. Typical victims of Aoqin Dragon's activities include government agencies, educational institutions, and telecommunication providers, all of which are likely to possess information of interest to the group.

Enhanced Description

Further analysis of Aoqin Dragon's activities reveals a sophisticated and coordinated approach to cyber espionage. The group's use of tailored malware and infrastructure suggests a high degree of planning and resources. Additionally, the group's ability to evade detection and persist in targeted networks for extended periods indicates a strong operational security posture. As more information becomes available, it is likely that Aoqin Dragon's TTPs will be further refined, providing a clearer understanding of the group's capabilities and intentions.

Key Capabilities

  • Tailored malware development
  • Sophisticated infrastructure deployment
  • Evasion and anti-detection techniques
  • Network persistence and lateral movement
  • Data exfiltration and exploitation

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom malware
Legitimate software exploitation

Campaigns & Victims

Aoqin Dragon's campaign patterns and operational tempo are not yet fully understood, but initial findings suggest a coordinated and targeted approach to cyber espionage. The group's activities appear to be focused on specific sectors and countries, with a preference for organizations with access to valuable data. Notable past operations include the targeting of government agencies, educational institutions, and telecommunication providers in Australia, Cambodia, Hong Kong, Singapore, and Vietnam.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust email filtering and employee education programs to prevent spear-phishing attacks
  • Deploy advanced threat detection and response capabilities to identify and mitigate Aoqin Dragon's activities
  • Conduct regular network audits and vulnerability assessments to identify potential entry points and weaknesses
  • Implement a robust incident response plan to quickly respond to and contain Aoqin Dragon's activities

Suggested Tags

APT
Cyber espionage
China

Confidence Assessment

The confidence level in the available data on Aoqin Dragon is moderate, with some information gaps existing regarding the group's motivations, goals, and TTPs. Further analysis and research are needed to fully understand the group's capabilities and intentions.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. SentinelOne Aoqin Dragon June 2022 — Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

Intel Summary

9

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

APT
Government Targeting

Details

MITRE ID
G1007
Type
Unknown
Country of Origin
C
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--64d5f96a-f121-4d19-89f6-6709f5c49faa
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.