Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
5 malware familiesExploits CVEs in the wild

Aoqin Dragon

Also known asAoqin Dragon

Aoqin Dragon is a cyberespionage threat actor tracked by SentinelLABS that has operated since at least 2013. It primarily targets government, education, and telecommunication organizations in Southeast Asia and Australia, including activity affecting Australia, Cambodia, Hong Kong, Singapore, and Vietnam. SentinelLABS assesses its primary motive as espionage and assesses with moderate confidence that it is a small Chinese-speaking team. SentinelLABS also noted a potential association with UNC94 based on overlapping targeting, malware artifacts, infrastructure, and Chinese-language development traces. The actor has used multiple user-execution and spearphishing-style lures, including weaponized Microsoft Word documents, fake antivirus executables, fake folder or external-drive themed files, and removable-media shortcut lures. Reported exploitation includes CVE-2012-0158 and CVE-2010-3333 in weaponized Word documents. From 2018 onward, it used fake removable-device lures and USB shortcut techniques, including a shortcut impersonating a removable disk that launched an "Evernote Tray Application" to trigger DLL hijacking. Aoqin Dragon relies heavily on DLL hijacking, process injection, obfuscation, and persistence. Its loader used DLL hijacking to load a malicious encrashrep.dll component as explorer.exe, decrypted payloads, and injected a backdoor into rundll32.exe memory. It established persistence via autostart values such as EverNoteTrayUService or EverNoteTrayService after copying modules into %USERPROFILE%\AppData\Roaming\EverNoteService. The group has also used the Themida packer to obfuscate payloads. The actor is associated with the Mongall backdoor and a modified version of the open-source Heyoka tool. Mongall has been used by the group since 2013 and supports remote shell access, file upload, and file download, communicating over HTTP GET with data encoded or encrypted using base64, modified base64, or RC4 depending on the variant. Aoqin Dragon also obtained and modified the open-source Heyoka project for its operations; the modified backdoor added hardcoded command-and-control servers, checked whether it was running as a system service, and supported shell access, file operations, process management, and host discovery. Additional observed behavior includes scripts to identify file formats including Microsoft Word, use of rar commands in droppers to archive targeted document types such as .doc and .docx, and use of a spreader component named "upan" to copy malicious modules to removable devices for propagation. Debug strings and PDB paths contained Simplified Chinese text and references including DLL_test, upan, Mongall, and DnsControl. Known aliases and related tracking in the provided content: aoqin_dragon; potential association with UNC94.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics56 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
T1595.002×2
Vulnerability Scanning
TA0042
Resource Development
2 techniques
T1587
Develop Capabilities
T1587.001×2
Malware
T1588
Obtain Capabilities
T1588.002×5
Tool
TA0001
Initial Access
3 techniques
T1091×4
Replication Through Removable Media
T1200×3
Hardware Additions
T1566
Phishing
T1566.001×2
Spearphishing Attachment
TA0002
Execution
6 techniques
T1059×3
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1129
Shared Modules
T1203×9
Exploitation for Client Execution
T1204×2
User Execution
T1204.002×13
Malicious File
T1569
System Services
T1574
Hijack Execution Flow
T1574.001
DLL
TA0003
Persistence
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
T1547.009
Shortcut Modification
TA0004
Privilege Escalation
3 techniques
T1055×3
Process Injection
T1055.001
Dynamic-link Library Injection
T1068
Exploitation for Privilege Escalation
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
T1547.009
Shortcut Modification
TA0005
Stealth
6 techniques
T1027
Obfuscated Files or Information
T1027.002×2
Software Packing
T1036×6
Masquerading
T1036.008
Masquerade File Type
T1055×3
Process Injection
T1055.001
Dynamic-link Library Injection
T1211
Exploitation for Stealth
T1564
Hide Artifacts
T1564.006
Run Virtual Instance
T1574
Hijack Execution Flow
T1574.001
DLL
TA0007
Discovery
4 techniques
T1033
System Owner/User Discovery
T1082×2
System Information Discovery
T1083×8
File and Directory Discovery
T1087
Account Discovery
T1087.002
Domain Account
TA0008
Lateral Movement
2 techniques
T1091×4
Replication Through Removable Media
T1570
Lateral Tool Transfer
TA0009
Collection
1 technique
T1560
Archive Collected Data
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1071.004×2
DNS
T1132
Data Encoding
T1571
Non-Standard Port
T1573
Encrypted Channel
TA0010
Exfiltration
3 techniques
T1041
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567
Exfiltration Over Web Service
IOCS

Observables

242 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping41

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs4

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables242

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Aoqin Dragon | Mallory