Cyber Resilience

Campaign · all campaigns

Night DragonC0002 state

🇨🇳 CN

aka Night Dragon, G0014

Last updated: 2026-08-20

0attributed CVEs
43ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[Night Dragon](https://attack.mitre.org/campaigns/C0002) was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.(Citation: McAfee Night Dragon)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0014

CrowdStrikenation-animal names

Night Dragon

How we know this

Data origin
MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
Techniques
MITRE ATT&CK STIX mappings — 43 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-426 / 4360%
CM-624 / 4356%
SI-320 / 4347%
CM-219 / 4344%
CA-718 / 4342%
AC-317 / 4340%
CM-716 / 4337%
AC-415 / 4335%
AC-615 / 4335%
SC-714 / 4333%
AC-213 / 4330%
IA-213 / 4330%
SI-713 / 4330%
AC-511 / 4326%
CM-59 / 4321%

Co-occurring actors

None.

Similar actors

Similar TTPs

Same nation-state