Introduction
Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets. SentinelOne Aoqin Dragon June 2022
Activities and Tactics
Targeted Sectors: Government, Education, Telecommunications
Country of Origin: 🇨🇳 China
Suspected Victims: Australia, Cambodia, Hong Kong, Singapore, Vietnam
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1204.002 Malicious File
- T1570 Lateral Tool Transfer
- T1091 Replication Through Removable Media
- T1027.002 Software Packing
- T1587.001 Malware
- T1083 File and Directory Discovery
- T1036 Masquerading
- T1588.002 Tool
- T1203 Exploitation for Client Execution
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- Backdoor.Oldrea
- Back Orifice
- Back Orifice 2000
- GraphicBooting
MITRE ATT&CK Software
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [2] SentinelOne Aoqin Dragon June 2022 Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.