Night Dragon
Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1003.001 1 report
- T1008 1 report
- T1016 1 report
- T1021.002 1 report
- T1027.001 1 report
- T1027.002 1 report
- T1033 1 report
- T1036.004 1 report
- T1036.005 1 report
- T1040 1 report
Show all 53 techniques Show fewer
- T1053.002 1 report
- T1053.005 1 report
- T1055 1 report
- T1055.001 1 report
- T1056.001 1 report
- T1057 1 report
- T1059.003 1 report
- T1059.005 1 report
- T1068 1 report
- T1069.002 1 report
- T1071.001 1 report
- T1071.004 1 report
- T1078.002 1 report
- T1082 1 report
- T1083 1 report
- T1087.001 1 report
- T1087.002 1 report
- T1090.001 1 report
- T1095 1 report
- T1105 1 report
- T1106 1 report
- T1112 1 report
- T1119 1 report
- T1132.001 1 report
- T1140 1 report
- T1197 1 report
- T1218.011 1 report
- T1543.003 1 report
- T1546.015 1 report
- T1547.001 1 report
- T1548.002 1 report
- T1553.002 1 report
- T1555.003 1 report
- T1560.001 1 report
- T1564.001 1 report
- T1566.001 1 report
- T1566.002 1 report
- T1569.002 1 report
- T1571 1 report
- T1572 1 report
- T1573.001 1 report
- T1614.001 1 report
- T1620 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2009-1539
- CVE-2009-3129 KEV
- CVE-2010-2568 KEV
- CVE-2010-3333 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2015-5119 KEV
- CVE-2017-0213 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The original link failed its last check. Original publisher Detailsfor Musical Chairs Playing Tetris
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Operation Shady RAT
-
Advanced Persistent Threats: A Decade In Review
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Advanced Persistent Threats: A Decade In Review
-
Command And Control In The Fifth Domain
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Command And Control In The Fifth Domain
-
Space Pirates analyzing the tools and connections of a new hacker group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Pirates analyzing the tools and connections of a new hacker group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Musical Chairs Playing Tetris
-
Important information about Night Dragon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Important information about Night Dragon
Show all 26 reports Show fewer
-
Musical Chairs: Multi-Year Campaign Involving New Variant of Gh0st Malware - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Musical Chairs: Multi-Year Campaign Involving New Variant of Gh0st Malware - Palo Alto Networks Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Musical Chairs: Multi-Year Campaign Involving New Variant of Gh0st Malware - Palo Alto Networks BlogPalo Alto Networks Blog
-
Securelist | The "Red October" Campaign - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Securelist | The "Red October" Campaign - Securelist
-
The Art of Attribution Identifying and Pursuing your Cyber Adversaries
The original link failed its last check. Original publisher Detailsfor The Art of Attribution Identifying and Pursuing your Cyber Adversaries
-
targeted_attacks_against_the_energy_sector
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor targeted_attacks_against_the_energy_sector
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Energy at risk
-
Energy At Risk: A Study Of It Security In The Energy And Natural Resources Industry
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Energy At Risk: A Study Of It Security In The Energy And Natural Resources Industry
-
Crude Faux: An Analysis Of Cyber Conflict Within The Oil & Gas Industries
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Crude Faux: An Analysis Of Cyber Conflict Within The Oil & Gas Industries
-
“Red October” – Part Two, the Modules
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “Red October” – Part Two, the Modules
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The “Red October” Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor enter-the-cyberdragon
-
Attachment 1 - Night Dragon Specific Protection Measures for Consideration
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Attachment 1 - Night Dragon Specific Protection Measures for Consideration
-
wp-global-energy-cyberattacks-night-dragon
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor wp-global-energy-cyberattacks-night-dragon
-
McAfee_NightDragon_wp_draft_to_customersv1-1.pdf
The original link failed its last check. Original publisher Detailsfor McAfee_NightDragon_wp_draft_to_customersv1-1.pdf
Newest first. Details opens the report in Explore.