DragonOK is a China-based cyber-espionage threat group assessed to operate from Jiangsu Province. It has principally targeted Japanese and Taiwanese manufacturing and high-technology organizations, with sustained activity against Japanese entities documented since at least 2014. DragonOK has used spearphishing attachments, malicious RTF documents exploiting Microsoft Office vulnerabilities, and watering-hole compromises to establish access. Its malware ecosystem includes Sysget (HelloBridge), IsSpace, NFlog, TidePool, PlugX variants including PIPX, FormerFirstRAT, and Rambo. The group uses staged downloaders and backdoors for host profiling, command execution, file transfer, and information collection. It has established persistence through autorun mechanisms and services, employed DLL side-loading, process injection, encrypted or obfuscated configuration and command-and-control traffic, anti-debugging and anti-virtual-machine checks, and deceptive icons and decoy documents. DragonOK is also connected in public reporting to Rancor, although this relationship does not establish that the groups are identical.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Sysget malware was delivered both directly via phishing emails, as well as in Rich Text Format (RTF) documents exploiting the CVE-2015-1641 vulnerability (patched in MS15-033) that in turn leveraged a very unique shellcode.
It was hosting an Adobe Flash exploit targeting one of the newly disclosed vulnerabilities from the Hacking Team data breach, CVE-2015-5122.
144 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a connected/related cluster to Rancor; no direct activity details provided in this text.
PlugX(PIPX)やSysget、Aveoに関連するインフラを用いた標的型攻撃活動。主に日本や台湾の製造業・ハイテク産業を標的として継続的に活動している。
Conducting targeted intrusion campaigns primarily against organizations in Japan, using phishing emails and malicious RTF documents exploiting CVE-2015-1641 to deliver Sysget, IsSpace, and TidePool malware.
Previously attributed user of the NFlog backdoor; likely relevant because IsSpace appears to be an evolution of NFlog.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.