Night Dragon· China
Night Dragon (G0014) is a threat actor using remote access trojans to steal oil field exploration data from the energy sector.
Analyst brief
Night Dragon (G0014) is a threat actor primarily targeting the energy and oil & gas sectors. They conduct targeted campaigns aimed at stealing proprietary oil field exploration data and operational secrets. Key TTPs include using remote access trojans to exfiltrate confidential data to external servers. Defenders should focus on anomalous outbound network connections and suspicious access attempts targeting industrial control systems, especially within the energy sector.
FAQ2
Which sectors does Night Dragon (G0014) primarily target?
Night Dragon primarily targets the energy and oil & gas sectors.
What network activities should defenders monitor for regarding the Night Dragon group?
Defenders should focus on anomalous outbound network connections and suspicious access attempts targeting industrial control systems, especially within the energy sector.
See also6
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.