Mongall is a custom DLL-based backdoor associated with the Aoqin Dragon espionage group and in use since at least 2013. Reporting describes it as a long-maintained malware family used primarily in cyberespionage operations targeting government, education, and telecommunications organizations, particularly in Southeast Asia and Australia; ESET previously reported Mongall activity targeting the Vietnamese government and a telecommunications department. Aoqin Dragon commonly deployed Mongall alongside a modified version of the open-source Heyoka project.
Observed infection and execution methods include user execution of malicious documents and later removable-media/shortcut-based lures used by Aoqin Dragon. In the latter tradecraft, loaders used DLL hijacking, decrypted payloads, and injected the Mongall backdoor into memory, including into rundll32.exe; Mongall can also use rundll32.exe for execution. The malware has been observed packed with Themida, and SentinelLABS reported newer variants with upgraded encryption.
Documented capabilities include remote shell access, file upload, file download, exfiltration of files and host information to command-and-control servers, removable-media discovery, and host profiling. Mongall can identify removable media attached to compromised hosts and can upload files from victim machines to its C2. Communications have been described as using HTTP GET with victim data encoded or encrypted using Base64, modified Base64, or RC4 depending on the variant/mutex. SentinelLABS also reported emulating a Mongall C2 server to capture beacon messages. High-confidence behavioral details directly mentioned in the source include DLL injection into rundll32.exe, Base64 use in C2 traffic, file upload capability, and removable-media identification.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During 2012 to 2015, Aoqin Dragon relied heavily on CVE-2012-0158 and CVE-2010-3333 to compromise their targets.
During 2012 to 2015, Aoqin Dragon relied heavily on CVE-2012-0158 and CVE-2010-3333 to compromise their targets.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Attacks attributable to Aoqin Dragon typically drop one of two backdoors, Mongall and a modified version of the open source Heyoka project.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
From 2018 to present, this actor has also been observed using a fake removable device as an initial infection vector... The spreader component will try to find the removable device in the victim’s environment. This malware component will copy all the malicious modules to any removable device to spread the malware in the target’s network environment
Using a document exploit and tricking the user into opening a weaponized Word document to install a backdoor. Luring users into double-clicking a fake Anti-Virus to execute malware in the victim’s host.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
After decrypting the encrypted payload, DLL-test.dll will execute rundll32.exe and run specific export functions. The loader injects the decrypted payload into memory and runs it persistently.
There are two payloads in this attack chain... the second one is an encrypted backdoor which injects itself into rundll32’s memory.
Other techniques the attacker has been observed using include DLL hijacking, Themida-packed files, and DNS tunneling to evade post-compromise detection... Actors using Thimda packer to pack the malwares
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
After decrypting the encrypted payload, DLL-test.dll will execute rundll32.exe and run specific export functions. The loader injects the decrypted payload into memory and runs it persistently.
There are two payloads in this attack chain... the second one is an encrypted backdoor which injects itself into rundll32’s memory.
MITRE ATT&CK TTPs ... Discovery T1033 – System Owner/User Discovery Collecting user account and send back to C2
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
From 2018 to present, this actor has also been observed using a fake removable device as an initial infection vector... The spreader component will try to find the removable device in the victim’s environment. This malware component will copy all the malicious modules to any removable device to spread the malware in the target’s network environment
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
Mongall uses base64 or RC4 to encode or encrypt data to make the content of command and control traffic more difficult to detect
211 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... Mongall ... (v1.0→v1.1) ...
Mongall (v1.0→v1.1)
A small backdoor active since at least 2013. It provides remote shell access, file upload/download capability, embeds multiple C2 servers, and communicates over HTTP using RC4 and/or Base64-obfuscated data in newer variants.
A backdoor used by Aoqin Dragon that is injected into memory as a DLL, protected with encryption, profiles the host, and sends system details to command-and-control over an encrypted channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.