Intrusion setG0017
DragonOK
DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.
- Documented techniques
- 0
- Basis
- MITRE ATT&CK
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
PlugXPoisonIvy