DragonOK

MITRE ATT&CK: G0017 View on attack.mitre.org

Aliases: Moafee, BRONZE OVERBROOK, Shallow Taurus, DragonOK

First seen
2013-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 12:31:54

Targeted industries: government-and-public-sector technology-and-telecommunications manufacturing

Targeted regions: country_code:jp

Context

DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.

Detection coverage

  • 11 YARA rules

Malware & tools used

Related threat objects

Reports & references

  • MITRE ATT&CK — Groups (report)
  • Mandiant — Wp Operation Quantum Entanglement (report)
  • forcepoint.com — Trojanized Adobe Installer Used Install Dragonok S New Custom Backdoor (report)
  • github.com — Deep%20Dive%20On%20The%20Dragonok%20Rambo%20Backdoor%20 %20Morphick%20Cyber%20Security (report)
  • cfr.org — Moafee (report)
  • Palo Alto Unit 42 — Unit 42 Identifies New Dragonok Backdoor Malware Deployed Against Japanese Targets (report)
  • Palo Alto Unit 42 — Unit42 Dragonok Updates Toolset Targets Multiple Geographic Regions (report)
  • phnompenhpost.com — Kingdom Targeted New Malware (report)
  • MITRE ATT&CK — G0017 (report)
  • MITRE ATT&CK — G0002 (report)
  • secureworks.com — Bronze Overbrook (report)
  • Palo Alto Unit 42 — Shallowtaurus (report)
  • researchcenter.paloaltonetworks.com — Unit 42 Identifies New Dragonok Backdoor Malware Deployed Against Japanese Targets (report)
  • web.archive.org — Wp Operation Quantum Entanglement (report)

External references