DragonRank is a China-linked, Chinese-speaking cybercrime group associated with financially motivated search engine optimization (SEO) fraud. It targets Microsoft Internet Information Services (IIS) web servers and uses BadIIS malware to turn compromised infrastructure into assets for search engine manipulation. Its operations also involve the PlugX backdoor, distinguishing its documented tooling from some other IIS-focused SEO-fraud clusters. DragonRank belongs to a broader ecosystem of actors using related IIS malware, but shared tools and similar techniques do not establish common operators. It is tracked separately from Earth Lamia, with no established collaboration between them, and is not an established alias of UAT-8099, WEBJACK, GhostRedirector, or Operation Rewrite. Technical overlaps with CL-STA-0048-associated PlugX activity have been observed, but do not establish that the two clusters are identical.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named China-linked operation previously observed targeting IIS servers.
China-aligned threat group observed targeting IIS web servers.
A financially motivated, China-linked cluster targeting IIS servers for SEO fraud. The report uses it as a comparison to highlight OP-512's greater investment in custom tooling and operational security.
Cybercrime group using BadIIS variants to compromise web servers for search engine manipulation and SEO fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.