Aoqin Dragon

MITRE ATT&CK: G1007 View on attack.mitre.org

Aliases: UNC94, Aoqin Dragon

First seen
2013-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:02:52

Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:au country_code:kh country_code:hk country_code:sg country_code:vn

Context

Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.

Detection coverage

  • 1 YARA rules
  • 128 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Software Packing (attack-pattern)
  • Malware (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Masquerading (attack-pattern)
  • Tool (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Mongall (malware)
  • Heyoka Backdoor (malware)

Reports & references

  • sentinelone.com — Aoqin Dragon Newly Discovered Chinese Linked Apt Has Been Quietly Spying On Organizations For 10 Years (report)
  • khonggianmang.vn — Cb 941 Canhbao Apt 36C5A857Fa (report)
  • MITRE ATT&CK — G1007 (report)

External references