LiveActive security incident?Get immediate response
MITRE ATT&CK® Campaign

C0002: Night Dragon

Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.[1]

EnterpriseC0002CampaignObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Night Dragon matters because it represents an espionage campaign focused on energy-sector business and operationally sensitive information, including oil and gas production systems, financials, executive targets, and SCADA-related data. For leaders, the decision value is not the campaign name itself; it is the pattern of risk: externally reachable systems, valid account abuse, credential theft, remote administration tools, web shells, command-and-control over web protocols, data staging, and collection from local systems and email can combine into a long-running compromise of business and operational intelligence.

Executive priority

Treat this as a governance and resilience case study for energy, petrochemical, and similar industrial organizations. Priority questions include: Are public-facing applications and external remote services controlled and monitored? Are domain and local credentials protected well enough to prevent broad reuse? Can the SOC distinguish legitimate administrator use of tools such as PsExec and at from suspicious activity? Is there evidence collection across enterprise IT and any SCADA-adjacent environments sufficient for incident response, audit, and regulatory reporting? Budget should favor identity hardening, external attack surface reduction, endpoint and web-server telemetry, and response readiness for data theft investigations.

Technical view

ATT&CK relationships for Night Dragon include credential access against the Windows SAM, password cracking, valid and domain account abuse, external remote services, exploitation of public-facing applications, malicious links, Windows command shell execution, registry modification, file and user discovery, local email collection, local and remote data collection/staging, ingress tool transfer, web-protocol command-and-control, fallback channels, and obfuscation through packed or encrypted/encoded files. Related software includes gsecdump, PsExec, ASPXSpy, at, and zwShell. SOC and IR teams should validate whether they can reconstruct the chain from initial access through credential use, lateral execution, collection, staging, and outbound communications, especially on Windows hosts, web servers, remote access infrastructure, and systems that bridge business and operational data environments.

Likely telemetry

  • Authentication logs for VPN, external remote services, domain accounts, local accounts, and privileged accounts
  • Windows endpoint telemetry including process creation, command-line activity, registry changes, scheduled task or at usage, and security events related to credential access
  • Active Directory and identity-provider events for unusual domain account use, privilege changes, and abnormal login patterns
  • Web server and public-facing application logs for exploitation attempts, web shell behavior, suspicious uploads, and unusual command execution
  • EDR or host file telemetry for credential dumping tools, packed or encoded files, tool transfer, file discovery, email data access, and local data collection

Detection direction

  • Prioritize behavior-based detections over campaign-name matching, since the ATT&CK object provides no official detection text and the software includes tools that may also be used legitimately.
  • Tune for suspicious combinations: valid account use followed by PsExec or command shell execution, registry modification, credential dumping, discovery commands, data staging, and outbound web traffic.
  • Separate authorized administration from abuse by baselining where PsExec, at, command shells, and remote services are expected, who may use them, and from which management hosts.
  • Validate web shell coverage on Internet-facing applications, including file upload paths, anomalous script execution, unusual child processes from web services, and outbound connections from web servers.
  • Correlate credential theft indicators with subsequent domain account use, especially logins from unusual hosts, times, geographies, or remote access paths.

Mitigation priorities

  • Reduce exposure of public-facing applications and external remote services through inventory, patching, configuration review, strong authentication, and least-privilege access.
  • Harden identity controls first: protect domain accounts, restrict administrative privileges, monitor privileged use, and reduce opportunities for credential reuse after SAM or hash theft.
  • Constrain and monitor legitimate administration tools such as PsExec and at through approved-use policies, administrative tiering, and centralized logging.
  • Improve endpoint and server visibility for command execution, registry changes, credential dumping behavior, suspicious file transfer, and packed or encoded files.
  • Strengthen web application and web-server controls to reduce web shell risk, including secure configuration, file integrity monitoring where appropriate, and rapid investigation of suspicious uploads or script execution.
Additional notes and limits

The supplied ATT&CK object identifies Night Dragon as a past cyber espionage campaign targeting oil, energy, and petrochemical organizations and executives in Kazakhstan, Taiwan, Greece, and the United States. The official description states that researchers assessed the unidentified actors were based in China; this summary treats that as an assessment, not confirmed attribution. The strongest defensive value comes from the relationship set: credential theft and valid account abuse, web and remote access paths, administrative tool misuse, collection, staging, and command-and-control behaviors.

ATT&CK provides no official detection text, no object-level platforms or tactics, and no guaranteed sequence of activity for every intrusion. Platform and tactic references here are derived from the related software and techniques only. Local asset inventory, identity architecture, logging coverage, and business data flows are required to determine actual exposure and detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Night Dragon

Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

29 rows
DomainIDNameRelationship / procedure
EnterpriseT1078.002Domain AccountsSub-technique

During Night Dragon, threat actors used domain accounts to gain further access to victim systems.[1]

EnterpriseT1608.001Upload MalwareSub-technique

During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers.[1]

EnterpriseT1588.001MalwareSub-technique

During Night Dragon, threat actors used Trojans from underground hacker websites.[1]

EnterpriseT1566.002Spearphishing LinkSub-technique

During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded.[1]

EnterpriseT1204.001Malicious LinkSub-technique

During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware.[1]

EnterpriseT1133External Remote Services

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.[1]

EnterpriseT1005Data from Local System

During Night Dragon, the threat actors collected files and other data from compromised systems.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells.[1]

EnterpriseT1027.002Software PackingSub-technique

During Night Dragon, threat actors used software packing in its tools.[1]

EnterpriseT1190Exploit Public-Facing Application

During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access.[1]

EnterpriseT1078Valid Accounts

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.[1]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

During Night Dragon, threat actors used a DLL that included an XOR-encoded section.[1]

EnterpriseT1033System Owner/User Discovery

During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords.[1]

EnterpriseT1588.002ToolSub-technique

During Night Dragon, threat actors obtained and used tools such as gsecdump.[1]

EnterpriseT1112Modify Registry

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry.[1]

EnterpriseT1003.002Security Account ManagerSub-technique

During Night Dragon, threat actors dumped account hashes using gsecdump.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

During Night Dragon, threat actors used HTTP for C2.[1]

EnterpriseT1114.001Local Email CollectionSub-technique

During Night Dragon, threat actors used RAT malware to exfiltrate email archives.[1]

EnterpriseT1008Fallback Channels

During Night Dragon, threat actors used company extranet servers as secondary C2 servers.[1]

EnterpriseT1685Disable or Modify Tools

During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet.[1]

EnterpriseT1083File and Directory Discovery

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system.[1]

EnterpriseT1583.004ServerSub-technique

During Night Dragon, threat actors purchased hosted services to use for C2.[1]

EnterpriseT1550.002Pass the HashSub-technique

During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers.[1]

EnterpriseT1219Remote Access Tools

During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels.[1]

EnterpriseT1110.002Password CrackingSub-technique

During Night Dragon, threat actors used Cain & Abel to crack password hashes.[1]

EnterpriseT1584.004ServerSub-technique

During Night Dragon, threat actors compromised web servers to use for C2.[1]

EnterpriseT1568Dynamic Resolution

During Night Dragon, threat actors used dynamic DNS services for C2.[1]

EnterpriseT1105Ingress Tool Transfer

During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.[1]

EnterpriseT1074.002Remote Data StagingSub-technique

During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them.[1]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0008: gsecdump

gsecdump is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows operating systems. [1]

Windows
ToolEnterprise

S0110: at

at is used to schedule tasks on a system to run at a specified date or time.[1][2]

LinuxWindowsmacOS
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
1642ffd6d3985d3e...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle1642ffd6d398…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  2. [2]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  3. [3]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  4. [4]
    mitre-attackC0002
    Open source URL
  5. [5]
    mitre-attackC0002
    Open source URL
  6. [6]
    mitre-attackC0002
    Open source URL
  7. [7]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  8. [8]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  9. [9]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  10. [10]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  11. [11]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  12. [12]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  13. [13]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  14. [14]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  15. [15]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  16. [16]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  17. [17]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  18. [18]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  19. [19]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  20. [20]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  21. [21]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  22. [22]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  23. [23]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  24. [24]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  25. [25]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  26. [26]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  27. [27]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  28. [28]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  29. [29]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  30. [30]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  31. [31]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  32. [32]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  33. [33]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  34. [34]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  35. [35]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  36. [36]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  37. [37]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  38. [38]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  39. [39]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  40. [40]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  41. [41]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  42. [42]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  43. [43]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  44. [44]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  45. [45]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  46. [46]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  47. [47]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  48. [48]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  49. [49]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  50. [50]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  51. [51]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  52. [52]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  53. [53]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  54. [54]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  55. [55]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  56. [56]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  57. [57]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  58. [58]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  59. [59]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  60. [60]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  61. [61]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  62. [62]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  63. [63]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  64. [64]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  65. [65]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  66. [66]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  67. [67]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  68. [68]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  69. [69]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  70. [70]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.