ATT&CKCampaignsNight Dragon

Night Dragon

C0002

Campaign, Nov 2009 to Feb 2011.View on attack.mitre.org

About this campaign

Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.

Techniques used29

Procedure examples29

TechniqueProcedure example
T1003.002
Security Account Manager

During Night Dragon, threat actors dumped account hashes using gsecdump.

T1005
Data from Local System

During Night Dragon, the threat actors collected files and other data from compromised systems.

T1008
Fallback Channels

During Night Dragon, threat actors used company extranet servers as secondary C2 servers.

T1027.002
Software Packing

During Night Dragon, threat actors used software packing in its tools.

T1027.013
Encrypted/Encoded File

During Night Dragon, threat actors used a DLL that included an XOR-encoded section.

T1033
System Owner/User Discovery

During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords.

T1059.003
Windows Command Shell

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells.

T1071.001
Web Protocols

During Night Dragon, threat actors used HTTP for C2.

T1074.002
Remote Data Staging

During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them.

T1078
Valid Accounts

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1078.002
Domain Accounts

During Night Dragon, threat actors used domain accounts to gain further access to victim systems.

T1083
File and Directory Discovery

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system.

T1105
Ingress Tool Transfer

During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.

T1110.002
Password Cracking

During Night Dragon, threat actors used Cain & Abel to crack password hashes.

T1112
Modify Registry

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry.

View all 29 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software5

References1

  1. McAfee Night Dragon Open source
    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.