← All actors Recent activity

DragonOK G0017

DRAGONOK

Indicators
15
Source reports
6
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20172024

Overview 15 indicators

DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.

domain14G0017-domain.txt
url_path1G0017.json

Software 2

Principal sources 6 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 15 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 1 domain2 yrs ago

    researchcenter.paloaltonetworks.com/2015/04/unit-42-identifies-new-dragonok… · app.validin.com/detail?find=153.234.67.222&type=ip4&ref…

    donkeyhaws.info

  2. 4 domain, 1 url_path6 yrs ago

    lac.co.jp/english/report/2018/01/23_alert_01.html · app.any.run/tasks/ceb18346-8e01-4abe-89b9-97b44b14c…

    domainbbs.donkeyhaws.info
    domainhttp.donkeyhaws.info
    domainhttps.osakaintec.com
    domainphp.marbletemps.com
    url_path/XpXpXp

  3. 7 domain8 yrs ago

    fireeye.com/content/dam/fireeye-www/global/en/curre…

    ghostale.com
    jpaols.com
    moafee.com
    ndbssh.com
    pktmedia.com
    skyppee.com
    ycbackap.com

  4. 1 domain8 yrs ago

    researchcenter.paloaltonetworks.com/2015/04/unit-42-identifies-new-dragonok… · app.validin.com/detail?find=153.234.67.222&type=ip4&ref…

    biosnews.info

  5. 1 domain9 yrs ago

    morphick.com/resources/news/deep-dive-dragonok-rambo…

    busserh.mancely.com

Further reading 9