FORENSIA

THREAT_ACTOR · G0017

DragonOK

Also known as: DragonOK

Profile

DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.

MITRE ATT&CK ↗

Techniques

0 ATT&CK techniques attributed to this actor.

No techniques mapped.

Software

2 malware/tools attributed to this actor.

PoisonIvyPlugX

Related corpus activity

0 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to DragonOK.

No corpus indicators currently exhibit this actor’s techniques.