Threat actor · all actors
Aoqin DragonG1007 state
🇨🇳 CN
aka Aoqin Dragon, UNC94
Last updated: 2026-08-22
About this actor
SentinelLabs has uncovered a cluster of activity beginning at least as far back as 2013 and continuing to the present day, primarily targeting organizations in Southeast Asia and Australia. They assess that the threat actor's primary focus is espionage and relates to targets in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. We track this activity as 'Aoqin Dragon'. The threat actor has a history of using document lures with pornographic themes to infect users and makes heavy use of USB shortcut techniques to spread the malware and infect additional targets. Attacks attributable to Aoqin Dragon typically drop one of two backdoors, Mongall and a modified version of the open source Heyoka project.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 13 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2022 — 1 KEV added
- 2010 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2010-3333 KEV | 8.5 | 7.8 | 0.9740 | 2010-11-10 | see CVE |
T1027Obfuscated Files or Information ↗T1027.002Software Packing ↗T1036Masquerading ↗T1083File and Directory Discovery ↗T1091Replication Through Removable Media ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.002Malicious File ↗T1570Lateral Tool Transfer ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-3 | 8 / 13 | 62% |
SI-4 | 8 / 13 | 62% |
CM-2 | 6 / 13 | 46% |
CM-6 | 6 / 13 | 46% |
SI-7 | 6 / 13 | 46% |
CA-7 | 5 / 13 | 38% |
CM-7 | 5 / 13 | 38% |
AC-3 | 4 / 13 | 31% |
AC-4 | 4 / 13 | 31% |
SC-7 | 4 / 13 | 31% |
SI-10 | 4 / 13 | 31% |
SI-2 | 4 / 13 | 31% |
AC-6 | 3 / 13 | 23% |
SC-44 | 3 / 13 | 23% |
CM-8 | 2 / 13 | 15% |
Co-occurring actors
- Scarlet Mimic 1 shared CVEs
- Transparent Tribe 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Naikon 1 shared CVEs
Similar actors
Similar TTPs
- Whitefly 0.27
- Ferocious Kitten 0.26
- Elderwood 0.25
- The White Company 0.25
- Triton Safety Instrumented System Attack 0.24
Overlapping CVEs
- Naikon 1.00
- Transparent Tribe 1.00
- Sandworm Team 0.50
- Scarlet Mimic 0.33
Active in same years
- APT29 2.00
- Naikon 2.00
- Equation 2.00
- Threat Group-3390 2.00
- Scarlet Mimic 2.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00