Moshen Dragon

First seen
2020-05-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:09:50

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:kz country_code:uz country_code:kg country_code:tm country_code:tj

Context

Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia. They have been observed deploying multiple malware triads and utilizing DLL search order hijacking to sideload ShadowPad and PlugX variants. The threat actor also employs various tools, including an LSA notification package and a passive backdoor known as GUNTERS. Their activities involve targeting the telecommunication sector and leveraging Impacket for lateral movement and data exfiltration.

Reports & references

  • sentinelone.com — Moshen Dragons Triad And Error Approach Abusing Security Software To Sideload Plugx And Shadowpad (report)

External references