THREAT_ACTOR · G0017
DragonOK
Also known as: DragonOK
Profile
DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.
MITRE ATT&CK ↗Techniques
0 ATT&CK techniques attributed to this actor.
No techniques mapped.
Software
2 malware/tools attributed to this actor.
PoisonIvyPlugX
Related corpus activity
0 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to DragonOK.
No corpus indicators currently exhibit this actor’s techniques.