DragonOK is a Chinese cyber-espionage threat group assessed to operate from Jiangsu, China and known for sustained targeting of organizations in East Asia, especially Japan and Taiwan. Reported victim sectors include manufacturing, high technology, semiconductors, energy, and government-related entities, with activity also extending to victims of interest connected to Tibet and Russia. DragonOK has been publicly linked to malware families including Sysget (also known as HelloBridge), IsSpace, NFlog, TidePool, PlugX, PoisonIvy, NewCT, FormerFirstRAT, FF-RAT, PIPX, and Rambo. Some reporting also notes connections between DragonOK and clusters or activity referred to as Bronze Overbrook, Danti, and Rancor. DragonOK commonly relies on spearphishing with decoy documents and malicious attachments, and has also used malicious RTF documents exploiting Microsoft Office vulnerabilities and watering-hole compromises. The group is notable for repeated abuse of DLL sideloading using legitimate signed software, including tradecraft involving PotPlayer and VMware-related binaries, as well as process injection and multi-stage loaders. Its malware has demonstrated persistence through Run-key mechanisms, service installation, startup-folder execution, and PowerShell-based autoruns. DragonOK tooling supports host reconnaissance, command execution, file upload and download, payload staging, and data exfiltration. Observed samples also include anti-debugging, anti-virtual-machine, emulator-evasion, encrypted configuration storage, and obfuscated command-and-control communications. Sysget has served as a recurring first-stage implant in DragonOK operations, often used to establish footholds and retrieve additional backdoors. Later variants incorporated stronger encryption, modified network protocols, and anti-analysis features. IsSpace appears closely related to NFlog and has been used both in exploit-driven delivery chains and in later phishing campaigns, with capabilities including system profiling, command execution, file operations, and credential-related proxy collection. PlugX variants associated with DragonOK have used DLL sideloading, registry-stored payloads, service-based persistence, and code injection into legitimate processes. FormerFirstRAT and Rambo illustrate the group’s use of custom backdoors for post-compromise control, reconnaissance, and exfiltration. DragonOK’s activity is consistent with long-term intelligence collection rather than financially motivated crime. Its operational pattern emphasizes targeted intrusion, stealthy persistence, modular follow-on tooling, and continued refinement of malware families over multiple years.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Sysget malware was delivered both directly via phishing emails, as well as in Rich Text Format (RTF) documents exploiting the CVE-2015-1641 vulnerability (patched in MS15-033) that in turn leveraged a very unique shellcode.
It was hosting an Adobe Flash exploit targeting one of the newly disclosed vulnerabilities from the Hacking Team data breach, CVE-2015-5122.
144 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a connected/related cluster to Rancor; no direct activity details provided in this text.
PlugX(PIPX)やSysget、Aveoに関連するインフラを用いた標的型攻撃活動。主に日本や台湾の製造業・ハイテク産業を標的として継続的に活動している。
Conducting targeted intrusion campaigns primarily against organizations in Japan, using phishing emails and malicious RTF documents exploiting CVE-2015-1641 to deliver Sysget, IsSpace, and TidePool malware.
Previously attributed user of the NFlog backdoor; likely relevant because IsSpace appears to be an evolution of NFlog.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.