NEW: Group Profiler — instant APT intel lookup. Try it →

DragonOK

G0017 Espionage MITRE ATT&CK →

Overview

DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.

Naming & attribution

DragonOK is tracked under 1 names across the industry. It uses 0 documented ATT&CK techniques — more than 0% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
DragonOKHaq, T., Moran, N., Vashisht, S., Scott, M

Targets

Private sector

Regions

United States

Tools & malware (2)

PoisonIvy · PlugX

Reporting (2)