Campaign, Nov 2009 to Feb 2011.View on attack.mitre.org
Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
During Night Dragon, threat actors dumped account hashes using gsecdump. |
| T1005 Data from Local System |
During Night Dragon, the threat actors collected files and other data from compromised systems. |
| T1008 Fallback Channels |
During Night Dragon, threat actors used company extranet servers as secondary C2 servers. |
| T1027.002 Software Packing |
During Night Dragon, threat actors used software packing in its tools. |
| T1027.013 Encrypted/Encoded File |
During Night Dragon, threat actors used a DLL that included an XOR-encoded section. |
| T1033 System Owner/User Discovery |
During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords. |
| T1059.003 Windows Command Shell |
During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells. |
| T1071.001 Web Protocols |
During Night Dragon, threat actors used HTTP for C2. |
| T1074.002 Remote Data Staging |
During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them. |
| T1078 Valid Accounts |
During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1078.002 Domain Accounts |
During Night Dragon, threat actors used domain accounts to gain further access to victim systems. |
| T1083 File and Directory Discovery |
During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system. |
| T1105 Ingress Tool Transfer |
During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems. |
| T1110.002 Password Cracking |
During Night Dragon, threat actors used Cain & Abel to crack password hashes. |
| T1112 Modify Registry |
During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.