DragonOK
MITRE: G0017DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.
Alternate names
n/a
DragonOK is an advanced persistent threat (APT) that has been identified by security researchers. It is believed to be linked to Chinese state-sponsored hacking groups and has targeted various organizations, including government agencies, military contractors, and media outlets. The group uses a variety of tactics, such as spear phishing emails and watering hole attacks, to gain access to their targets' networks. Once inside the network, DragonOK is able to steal sensitive information or install malware that can be used for further espionage activities.
Techniques, tactics and practices:
DragonOK is believed to use a variety of techniques, such as spear phishing emails that appear to be from trusted sources but contain malicious links or attachments. They also conduct watering hole attacks by targeting specific websites and injecting their own code into the site's content management system (CMS) to gain access to visitors' machines. Additionally, DragonOK is known for using sophisticated tools that can evade detection by antivirus software or other security measures. They also use a variety of tactics such as stealing credentials and installing malware on the compromised systems.
Alternate Group Names
BRONZE OVERBROOK, G0002, G0017, Moafee, Shallow Taurus,
Alternative Names
Dragon Castling, G0017,
