THREAT_ACTOR · G1007
Aoqin Dragon
Also known as: Aoqin Dragon
Profile
Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.
MITRE ATT&CK ↗Techniques
9 ATT&CK techniques attributed to this actor.
Software
2 malware/tools attributed to this actor.
MongallHeyoka Backdoor
Related corpus activity
9,148 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Aoqin Dragon.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2017-17215 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2025-7852 | cve | — | 85 | 1 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-34085 | cve | — | 85 | 1 |
| cve-2025-7443 | cve | — | 85 | 1 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2025-34037 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,148.