Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Moshen Dragon

Description

Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia. They have been observed deploying multiple malware triads and utilizing DLL search order hijacking to sideload ShadowPad and PlugX variants. The threat actor also employs various tools, including an LSA notification package and a passive backdoor known as GUNTERS. Their activities involve targeting the telecommunication sector and leveraging Impacket for lateral movement and data exfiltration.

AI Analysis

· 1 week ago

Executive Summary

Moshen Dragon is a Chinese-aligned cyberespionage threat actor targeting Central Asia, primarily focusing on the telecommunication sector. They employ advanced tactics such as DLL search order hijacking, LSA notification packages, and passive backdoors like GUNTERS. Their activities include deploying malware triads and leveraging tools like PlugX and ShadowPad for long-term access.

Goals & Targeting

Moshen Dragon's strategic objectives appear to revolve around cyberespionage and potentially disruptive activities in the telecommunication sector, likely to bolster Chinese geopolitical interests in Central Asia. The targeting of this specific sector suggests a focus on gaining access to critical infrastructure and sensitive communications data. Their victims are primarily located in regions aligned with or adjacent to China's Belt and Road Initiative, indicating a geostrategic targeting approach.

Enhanced Description

Moshen Dragon operates with a high level of sophistication, aligning their activities with Chinese-state interests in the Central Asian region. The threat actor has demonstrated a persistent and targeted approach to compromising telecommunication infrastructure, likely aiming to gather sensitive information or disrupt critical services. Their toolkit includes malicious software such as ShadowPad and PlugX, which are known for their persistence and data exfiltration capabilities. Moshen Dragon's tactics involveDLL search order hijacking to sideload these tools, indicating a preference for stealthy and reliable infection methods. The actor also utilizes LSA notification packages and a passive backdoor named GUNTERS, showcasing their ability to maintain long-term access to victim systems. Their use of Impacket for lateral movement underscores their capability to navigate across networks effectively.

Key Capabilities

  • DLL search order hijacking for malware deployment
  • Use of ShadowPad and PlugX malware variants
  • LSA notification package exploitation
  • Passive backdoor creation (GUNTERS)
  • Leveraging Impacket for lateral movement and data exfiltration

MITRE ATT&CK Tactics

Espionage
Data Theft
Network Access Maintenance

ATT&CK Techniques

T1059.003 - Remote Command and Control over .NET Remoting
T1055 - Process Injection
T1566.001 - OS Credential Dumping: Windows LSA Notification Packages

Software / Tooling

ShadowPad Malware
PlugX Backdoors
Impacket Framework
GUNTERS Passive Backdoor
LSA Notification Packages

Campaigns & Victims

Moshen Dragon has been active in Central Asia, conducting targeted campaigns against telecom entities. Their operations demonstrate a patient and methodical approach, often utilizing off-the-shelf tools and frameworks like Impacket for both persistence and lateral movement. The actor's campaigns are likely linked to broader Chinese state-sponsored espionage efforts.

IOC Patterns

  • Spear-phishing emails with malicious .LNK files ormacro-laced Office documents
  • DLL search order hijacking for fileless malware delivery
  • Unusual network traffic indicative of C2 communication using known ports
  • Use of LSA notification packages in system processes

Recommended Actions

  • Implement strong perimeter and endpoint detection mechanisms to detect DLL injection and .NET Remoting activity.
  • Monitor for unusual process behavior and network anomalies associated with Impacket usage.
  • Enhance logging capabilities to track LSA notifications and identify unauthorized backdoor activities.
  • Conduct regular patch management to mitigate vulnerabilities exploited by Moshen Dragon's tools.
  • Educate employees about phishing tactics and implement email filtering to block malicious payloads.

Suggested Tags

APT
China-aligned
Cyberespionage
Telecommunication Sector
Nation-state

Confidence Assessment

Confidence in Moshen Dragon's details is moderate, as some of their TTPs and exact campaign timelines remain unclear. Gaps include the lack of specific IOCs and a deeper understanding of their operational infrastructure.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
China-aligned
Cyberespionage
Telecommunication Sector
Nation-state

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.