Campaign · all campaigns
Night DragonC0002 state
🇨🇳 CN
aka Night Dragon, G0014
Last updated: 2026-08-20
About this actor
[Night Dragon](https://attack.mitre.org/campaigns/C0002) was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.(Citation: McAfee Night Dragon)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 43 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.002Security Account Manager ↗T1005Data from Local System ↗T1008Fallback Channels ↗T1027Obfuscated Files or Information ↗T1027.002Software Packing ↗T1027.013Encrypted/Encoded File ↗T1033System Owner/User Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.002Remote Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1083File and Directory Discovery ↗T1105Ingress Tool Transfer ↗T1110Brute Force ↗T1110.002Password Cracking ↗T1112Modify Registry ↗T1114Email Collection ↗T1114.001Local Email Collection ↗T1133External Remote Services ↗T1190Exploit Public-Facing Application ↗T1204User Execution ↗T1204.001Malicious Link ↗T1219Remote Access Tools ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1566Phishing ↗T1566.002Spearphishing Link ↗T1568Dynamic Resolution ↗T1583Acquire Infrastructure ↗T1583.004Server ↗T1584Compromise Infrastructure ↗T1584.004Server ↗T1588Obtain Capabilities ↗T1588.001Malware ↗T1588.002Tool ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1685Disable or Modify Tools ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 26 / 43 | 60% |
CM-6 | 24 / 43 | 56% |
SI-3 | 20 / 43 | 47% |
CM-2 | 19 / 43 | 44% |
CA-7 | 18 / 43 | 42% |
AC-3 | 17 / 43 | 40% |
CM-7 | 16 / 43 | 37% |
AC-4 | 15 / 43 | 35% |
AC-6 | 15 / 43 | 35% |
SC-7 | 14 / 43 | 33% |
AC-2 | 13 / 43 | 30% |
IA-2 | 13 / 43 | 30% |
SI-7 | 13 / 43 | 30% |
AC-5 | 11 / 43 | 26% |
CM-5 | 9 / 43 | 21% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- TA505 0.32
- Operation Spalax 0.29
- C0021 0.28
- Sea Turtle 0.28
- GALLIUM 0.28
Same nation-state
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
- KV Botnet Activity 1.00
Same category
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00
- Operation Ghost 1.00