DragonOK

APT / StateG0017 ↗
SourceMITRE ATT&CK
State sponsor: ChinaAttribution confidence: 50%Target categories: Private sector
Targeted regions: United States
Also known as:BRONZE OVERBROOKG0002G0017MoafeeShallow Taurus

About the group

DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

DragonOK uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →