ATT&CKReferencesSentinelOne Aoqin Dragon June 2022

SentinelOne Aoqin Dragon June 2022

Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples39

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMongall

Mongall has the ability to upload files from victim's machines.

T1007
System Service Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can check if it is running as a service on a compromised host.

T1027.002
Software Packing
GroupAoqin Dragon

Aoqin Dragon has used the Themida packer to obfuscate malicious payloads.

T1027.002
Software Packing
MalwareMongall

Mongall has been packed with Themida.

T1027.013
Encrypted/Encoded File
MalwareHeyoka Backdoor

Heyoka Backdoor can encrypt its payload.

T1036
Masquerading
GroupAoqin Dragon

Aoqin Dragon has used fake icons including antivirus and external drives to disguise malicious payloads.

T1036.004
Masquerade Task or Service
MalwareHeyoka Backdoor

Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service.

T1041
Exfiltration Over C2 Channel
MalwareMongall

Mongall can upload files and information from a compromised host to its C2 server.

T1055.001
Dynamic-link Library Injection
MalwareHeyoka Backdoor

Heyoka Backdoor can inject a DLL into rundll32.exe for execution.

T1055.001
Dynamic-link Library Injection
MalwareMongall

Mongall can inject a DLL into `rundll32.exe` for execution.

T1057
Process Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can gather process information.

T1070.004
File Deletion
MalwareHeyoka Backdoor

Heyoka Backdoor has the ability to delete folders and files from a targeted system.

T1071.001
Web Protocols
MalwareMongall

Mongall can use HTTP for C2 communication.

T1071.004
DNS
MalwareHeyoka Backdoor

Heyoka Backdoor can use DNS tunneling for C2 communications.

T1082
System Information Discovery
MalwareMongall

Mongall can retrieve the hostname via `gethostbyname`.

T1083
File and Directory Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor has the ability to search the compromised host for files.

T1083
File and Directory Discovery
GroupAoqin Dragon

Aoqin Dragon has run scripts to identify file formats including Microsoft Word.

T1091
Replication Through Removable Media
GroupAoqin Dragon

Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment.

T1105
Ingress Tool Transfer
MalwareMongall

Mongall can download files to targeted systems.

T1120
Peripheral Device Discovery
MalwareMongall

Mongall can identify removable media attached to compromised hosts.

T1120
Peripheral Device Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can identify removable media attached to victim's machines.

T1132.001
Standard Encoding
MalwareMongall

Mongall can use Base64 to encode information sent to its C2.

T1140
Deobfuscate/Decode Files or Information
MalwareMongall

Mongall has the ability to decrypt its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareHeyoka Backdoor

Heyoka Backdoor can decrypt its payload prior to execution.

T1203
Exploitation for Client Execution
GroupAoqin Dragon

Aoqin Dragon has exploited CVE-2012-0158 and CVE-2010-3333 for execution against targeted systems.

T1204.002
Malicious File
MalwareMongall

Mongall has relied on a user opening a malicious document for execution.

T1204.002
Malicious File
GroupAoqin Dragon

Aoqin Dragon has lured victims into opening weaponized documents, fake external drives, and fake antivirus to execute malicious payloads.

T1204.002
Malicious File
MalwareHeyoka Backdoor

Heyoka Backdoor has been spread through malicious document lures.

T1218.011
Rundll32
MalwareMongall

Mongall can use `rundll32.exe` for execution.

T1218.011
Rundll32
MalwareHeyoka Backdoor

Heyoka Backdoor can use rundll32.exe to gain execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareMongall

Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeyoka Backdoor

Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1570
Lateral Tool Transfer
GroupAoqin Dragon

Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices.

T1572
Protocol Tunneling
MalwareHeyoka Backdoor

Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers.

T1573.001
Symmetric Cryptography
MalwareMongall

Mongall has the ability to RC4 encrypt C2 communications.

T1587.001
Malware
GroupAoqin Dragon

Aoqin Dragon has used custom malware, including Mongall and Heyoka Backdoor, in their operations.

T1588.002
Tool
GroupAoqin Dragon

Aoqin Dragon obtained the Heyoka open source exfiltration tool and subsequently modified it for their operations.

T1680
Local Storage Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can enumerate drives on a compromised host.

T1680
Local Storage Discovery
MalwareMongall

Mongall can identify drives on compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.