DragonOK is a China-based nation-state actor known for targeting the US private sector via phishing and PlugX/PoisonIvy RATs.
Analyst brief
DragonOK is a China-based nation-state threat actor, also tracked as Moafee and BRONZE OVERBROOK, known for targeting the US private sector. It leverages phishing campaigns, historically against Japanese organizations, to gain initial access, deploying malware like PoisonIvy and PlugX. The group employs TTPs such as Binary Padding for stealth and maintains infrastructure for remote access trojans. Defenders should prioritize phishing awareness training and monitor for C2 indicators associated with PlugX and PoisonIvy.
DragonOK
MoafeeBRONZE OVERBROOKG0017
nation-state
Threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. 2223 It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)