Aoqin Dragon
MITRE ATT&CK: G1007 View on attack.mitre.org
Aliases: UNC94, Aoqin Dragon
- First seen
- 2013-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:02:52
Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:au country_code:kh country_code:hk country_code:sg country_code:vn
Context
Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.
Detection coverage
- 1 YARA rules
- 128 Sigma rules
Malware & tools used
- Malicious File (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Software Packing (attack-pattern)
- Malware (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Masquerading (attack-pattern)
- Tool (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Mongall (malware)
- Heyoka Backdoor (malware)
Reports & references
- sentinelone.com — Aoqin Dragon Newly Discovered Chinese Linked Apt Has Been Quietly Spying On Organizations For 10 Years (report)
- khonggianmang.vn — Cb 941 Canhbao Apt 36C5A857Fa (report)
- MITRE ATT&CK — G1007 (report)