C0002: Night Dragon
Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.[1]
Security context for executives and security teams
C0002: Night Dragon describes [Night Dragon](https://attack.mitre.org/campaigns/C0002) was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat gr...
Executive priority
C0002: Night Dragon is an official MITRE ATT&CK campaign. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate C0002: Night Dragon by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether C0002: Night Dragon appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Night Dragon
Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1078.002 | Domain AccountsSub-technique | During Night Dragon, threat actors used domain accounts to gain further access to victim systems.[1] |
| Enterprise | T1608.001 | Upload MalwareSub-technique | During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers.[1] |
| Enterprise | T1588.001 | MalwareSub-technique | During Night Dragon, threat actors used Trojans from underground hacker websites.[1] |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded.[1] |
| Enterprise | T1204.001 | Malicious LinkSub-technique | During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware.[1] |
| Enterprise | T1133 | External Remote Services | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.[1] |
| Enterprise | T1005 | Data from Local System | During Night Dragon, the threat actors collected files and other data from compromised systems.[1] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells.[1] |
| Enterprise | T1027.002 | Software PackingSub-technique | During Night Dragon, threat actors used software packing in its tools.[1] |
| Enterprise | T1190 | Exploit Public-Facing Application | During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access.[1] |
| Enterprise | T1078 | Valid Accounts | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.[1] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | During Night Dragon, threat actors used a DLL that included an XOR-encoded section.[1] |
| Enterprise | T1033 | System Owner/User Discovery | During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords.[1] |
| Enterprise | T1588.002 | ToolSub-technique | During Night Dragon, threat actors obtained and used tools such as gsecdump.[1] |
| Enterprise | T1112 | Modify Registry | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry.[1] |
| Enterprise | T1003.002 | Security Account ManagerSub-technique | During Night Dragon, threat actors dumped account hashes using gsecdump.[1] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | During Night Dragon, threat actors used HTTP for C2.[1] |
| Enterprise | T1114.001 | Local Email CollectionSub-technique | During Night Dragon, threat actors used RAT malware to exfiltrate email archives.[1] |
| Enterprise | T1008 | Fallback Channels | During Night Dragon, threat actors used company extranet servers as secondary C2 servers.[1] |
| Enterprise | T1685 | Disable or Modify Tools | During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet.[1] |
| Enterprise | T1083 | File and Directory Discovery | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system.[1] |
| Enterprise | T1583.004 | ServerSub-technique | During Night Dragon, threat actors purchased hosted services to use for C2.[1] |
| Enterprise | T1550.002 | Pass the HashSub-technique | During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers.[1] |
| Enterprise | T1219 | Remote Access Tools | During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels.[1] |
| Enterprise | T1110.002 | Password CrackingSub-technique | During Night Dragon, threat actors used Cain & Abel to crack password hashes.[1] |
| Enterprise | T1584.004 | ServerSub-technique | During Night Dragon, threat actors compromised web servers to use for C2.[1] |
| Enterprise | T1568 | Dynamic Resolution | During Night Dragon, threat actors used dynamic DNS services for C2.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.[1] |
| Enterprise | T1074.002 | Remote Data StagingSub-technique | During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them.[1] |
Groups, software, and campaigns
S0008: gsecdump
S0073: ASPXSpy
ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version. [1]
S0350: zwShell
zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.[1]
S0110: at
S0029: PsExec
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.1 | Current bundle | 346ef226770a… | ||
| 19.1 | 1.1 | Older bundle | 1642ffd6d398… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]McAfee Night Dragon
McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.
Open source URL - [2]mitre-attackC0002Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
