Camaro Dragon

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:04:42

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical

Targeted regions: country_code:cn country_code:vn country_code:kh country_code:my country_code:la

Context

In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of tools mentioned in the Avast report in late 2022. The incident was attributed to Camaro Dragon, a Chinese-based espionage threat actor whose activities overlap with activities tracked by different researchers as Mustang Panda and LuminousMoth, whose focus is primarily on Southeast Asian countries and their close peers.

Reports & references

  • research.checkpoint.com — The Dragon Who Sold His Camaro Analyzing Custom Router Implant (report)
  • research.checkpoint.com — Beyond The Horizon Traveling The World On Camaro Dragons Usb Flash Drives (report)

External references