LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1026: Mongall

Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.[1]

EnterpriseS1026MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Mongall matters because ATT&CK describes it as a Windows backdoor with relationships to behaviors that support persistence, discovery, command-and-control, tool transfer, local data collection, and exfiltration over the C2 channel. For leaders, the decision value is not the malware name alone; it is whether Windows endpoint, network, and identity-adjacent telemetry can show when a backdoor is launched, persists, blends into web traffic, and stages or moves sensitive data.

Executive priority

Treat this as a validation case for Windows backdoor readiness: can the organization prove it collects enough endpoint and network evidence to support containment, scoping, and regulatory/audit questions after suspected espionage-style intrusion activity? Priority should go to controls and telemetry around user-executed malicious files, rundll32/DLL abuse, registry persistence, encoded or encrypted web-based C2, ingress tool transfer, and data leaving through existing C2 channels.

Technical view

ATT&CK provides no official detection text for Mongall, so SOC and detection engineering should pivot from the supplied relationships. Validate coverage for Windows execution from malicious files, rundll32-based proxy execution, DLL injection indicators, Registry Run Keys or Startup Folder persistence, system/local storage/peripheral discovery, packed or decoded payload artifacts, tool transfer, and HTTP/S-like C2 with standard encoding or symmetric cryptography. IR playbooks should assume that backdoor activity may combine endpoint artifacts with network sessions and data access evidence, rather than relying on a single malware signature.

Likely telemetry

  • Windows process creation and command-line telemetry, especially rundll32.exe and unusual child/parent process chains
  • DLL load, memory injection, and cross-process access events where available
  • Windows registry and Startup Folder modification events for persistence validation
  • File creation/modification events for downloaded tools, packed executables, decoded payloads, and user-opened malicious files
  • Endpoint evidence of system information, local storage, peripheral, and local data discovery

Detection direction

  • Build detections around behavior chains rather than the Mongall name: malicious file execution followed by rundll32/DLL activity, registry persistence, discovery, and outbound web traffic is more defensible than a single indicator.
  • Tune rundll32 and DLL-injection analytics carefully because legitimate software may use similar mechanisms; prioritize rare DLL paths, suspicious parent processes, unsigned or newly written DLLs, and execution from user-writable locations.
  • Correlate endpoint discovery activity with network egress and tool-transfer evidence to reduce false positives and improve incident scoping.
  • Review blind spots in encrypted or encoded web traffic: ATT&CK relationships include Web Protocols, Standard Encoding, Symmetric Cryptography, and Exfiltration Over C2 Channel, which can limit payload visibility.
  • Because official detection guidance is not supplied, require local baselining and test data before declaring coverage.

Mitigation priorities

  • Prioritize endpoint hardening and monitoring for Windows execution paths commonly abused by backdoors, including user-writable directories, rundll32 execution, DLL loading, and Run Key or Startup Folder persistence.
  • Reduce initial execution risk through user-focused controls for malicious files and attachment handling, without assuming this alone prevents compromise.
  • Restrict and monitor outbound web traffic so C2 and tool transfer are more likely to be logged, inspected, or blocked according to business policy.
  • Strengthen least-privilege and application control where feasible to limit persistence, DLL abuse, and unauthorized tool execution.
  • Ensure incident response procedures preserve endpoint, registry, file, and network evidence needed to determine collection and exfiltration scope.
Additional notes and limits

The relationship to Aoqin Dragon provides threat-intelligence context: ATT&CK states that Mongall has been used since at least 2013, including by that group. The supplied relationships are the strongest source of defensive direction and map the malware to execution, persistence, stealth, discovery, command-and-control, collection, and exfiltration behaviors. Use this as a coverage-mapping object for managed detection, IR readiness, and security control validation on Windows environments.

ATT&CK supplies no official detection text, no aliases, no labels, and no explicit malware tactic list for Mongall. The provided object states Windows as the malware platform, while several related techniques have broader platform listings; this take does not infer non-Windows Mongall activity. No indicators of compromise, procedures, active exploitation claims, or customer exposure details are supplied, so local telemetry and threat intelligence are required for operational conclusions.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Mongall

Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1071.001Web ProtocolsSub-technique

Mongall can use HTTP for C2 communication.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Mongall has the ability to decrypt its payload prior to execution.[1]

EnterpriseT1204.002Malicious FileSub-technique

Mongall has relied on a user opening a malicious document for execution.[1]

EnterpriseT1120Peripheral Device Discovery

Mongall can identify removable media attached to compromised hosts.[1]

EnterpriseT1680Local Storage Discovery

Mongall can identify drives on compromised hosts.[1]

EnterpriseT1573.001Symmetric CryptographySub-technique

Mongall has the ability to RC4 encrypt C2 communications.[1]

EnterpriseT1218.011Rundll32Sub-technique

Mongall can use `rundll32.exe` for execution.[1]

EnterpriseT1005Data from Local System

Mongall has the ability to upload files from victim's machines.[1]

EnterpriseT1132.001Standard EncodingSub-technique

Mongall can use Base64 to encode information sent to its C2.[1]

EnterpriseT1105Ingress Tool Transfer

Mongall can download files to targeted systems.[1]

EnterpriseT1041Exfiltration Over C2 Channel

Mongall can upload files and information from a compromised host to its C2 server.[1]

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Mongall can inject a DLL into `rundll32.exe` for execution.[1]

EnterpriseT1082System Information Discovery

Mongall can retrieve the hostname via `gethostbyname`.[1]

EnterpriseT1027.002Software PackingSub-technique

Mongall has been packed with Themida.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1007: Aoqin Dragon

Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
d64e7df41bb5e208...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundled64e7df41bb5…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  2. [2]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  3. [3]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  4. [4]
    mitre-attackS1026
    Open source URL
  5. [5]
    mitre-attackS1026
    Open source URL
  6. [6]
    mitre-attackS1026
    Open source URL
  7. [7]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  8. [8]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  9. [9]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  10. [10]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  11. [11]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  12. [12]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  13. [13]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  14. [14]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  15. [15]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  16. [16]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  17. [17]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  18. [18]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  19. [19]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  20. [20]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  21. [21]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  22. [22]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  23. [23]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  24. [24]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  25. [25]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  26. [26]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  27. [27]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  28. [28]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  29. [29]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  30. [30]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  31. [31]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  32. [32]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  33. [33]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  34. [34]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  35. [35]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  36. [36]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.