The DragonOK espionage group was linked to a renewed wave of targeted intrusions against organizations in Japan and other parts of Asia, using updated malware families including PlugX variants, Sysget, IsSpace, and TidePool. Researchers tied a PlugX variant known as PIPX to DragonOK through overlapping command-and-control infrastructure, domain registration patterns, and tradecraft previously associated with the group. The activity primarily targeted manufacturing and high-tech organizations in Japan and Taiwan, while related reporting also identified likely victims in Tibet and Russia.
The attacks used phishing emails, malicious executables, and weaponized RTF documents exploiting CVE-2015-1641, alongside techniques such as DLL sideloading, code injection into nslookup.exe, and persistence through services, autorun registry keys, and PowerShell-based registry changes. DragonOK’s newer tooling showed stronger encryption, anti-debugging and anti-VM protections, altered command-and-control communications, and an unusual method of storing encrypted payloads in registry values such as HKLM\SOFTWARE\BINARY or HKCU\SOFTWARE\BINARY instead of loading directly from disk. The combined reporting indicates the group was actively refining its malware and broadening operations while maintaining a strong focus on Japanese targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
The LAC analysts confirmed Sysget use again in a targeted attack in late November 2017 and assessed the sample as a Sysget v4 variant.
A campaign observed around October 2017 used the files mcoemcpy.exe, mcutil.dll, and either Mlog.dat or mcafee.res to run the PIPX malware chain.
Analysts observed multiple targeted attacks from around October 2017 using the PIPX PlugX variant, delivered in RAR self-extracting archives and executed through DLL sideloading and code injection into nslookup.exe.
The LAC report says DragonOK's activity targeting Japan became more noticeable again from late October 2017, indicating a renewed wave of operations.
JPCERT/CC had previously reported a PlugX sample that used Poison Ivy API hash code, a detail later referenced in the LAC analysis of related malware activity.
A PIPX PlugX variant was observed around April 2016 using the files RasTls.exe, RasTls.dll, and RasTls.dll.msc as part of its execution chain.
A September 2015 report analyzed a new variant of the NfLog RAT, also known as IsSpace, and attributed its use to SAMURAI PANDA. The malware was reportedly deployed using a repurposed Hacking Team Adobe Flash exploit for CVE-2015-5122 and proxied C2 traffic through Google App Engine.
Unit 42 identified five phishing attacks conducted between January and March 2015 against Japanese organizations, primarily a manufacturing firm and later a high-tech organization, and attributed the activity to DragonOK. The campaign used Sysget/HelloBridge as a first-stage payload and revealed a newly identified custom backdoor, FormerFirstRAT, alongside other DragonOK-associated tools.
The LAC report states that the Sysget malware family, associated with DragonOK, had been used in targeted attacks in Japan since at least 2014.
LAC assessed that the PIPX PlugX variant was strongly linked to DragonOK based on overlapping infrastructure, registrant data, and ties to domains and malware families such as Aveo and Sysget.
Unit 42 attributed multiple recent attacks to DragonOK and reported the group was delivering updated Sysget variants, along with IsSpace and TidePool, via phishing emails and malicious RTF documents exploiting CVE-2015-1641. Japan was the primary target, with likely additional targeting in Taiwan, Tibet, and Russia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
lac.co.jp
Open sourceresearchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourcewikileaks.org
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.