DragonOK
MITRE ATT&CK: G0017 View on attack.mitre.org
Aliases: Moafee, BRONZE OVERBROOK, Shallow Taurus, DragonOK
- First seen
- 2013-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 12:31:54
Targeted industries: government-and-public-sector technology-and-telecommunications manufacturing
Targeted regions: country_code:jp
Context
DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.
Detection coverage
- 11 YARA rules
Malware & tools used
Related threat objects
- Moafee (threat-actor)
Reports & references
- MITRE ATT&CK — Groups (report)
- Mandiant — Wp Operation Quantum Entanglement (report)
- forcepoint.com — Trojanized Adobe Installer Used Install Dragonok S New Custom Backdoor (report)
- github.com — Deep%20Dive%20On%20The%20Dragonok%20Rambo%20Backdoor%20 %20Morphick%20Cyber%20Security (report)
- cfr.org — Moafee (report)
- Palo Alto Unit 42 — Unit 42 Identifies New Dragonok Backdoor Malware Deployed Against Japanese Targets (report)
- Palo Alto Unit 42 — Unit42 Dragonok Updates Toolset Targets Multiple Geographic Regions (report)
- phnompenhpost.com — Kingdom Targeted New Malware (report)
- MITRE ATT&CK — G0017 (report)
- MITRE ATT&CK — G0002 (report)
- secureworks.com — Bronze Overbrook (report)
- Palo Alto Unit 42 — Shallowtaurus (report)
- researchcenter.paloaltonetworks.com — Unit 42 Identifies New Dragonok Backdoor Malware Deployed Against Japanese Targets (report)
- web.archive.org — Wp Operation Quantum Entanglement (report)