Cyber Resilience

Threat actor · all actors

Aoqin DragonG1007 state

🇨🇳 CN

aka Aoqin Dragon, UNC94

Last updated: 2026-08-22

1attributed CVEs
13ATT&CK techniques
2.7IDF score (tooling uniqueness)
0exclusive CVEs
2010–2022years active

About this actor

SentinelLabs has uncovered a cluster of activity beginning at least as far back as 2013 and continuing to the present day, primarily targeting organizations in Southeast Asia and Australia. They assess that the threat actor's primary focus is espionage and relates to targets in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. We track this activity as 'Aoqin Dragon'. The threat actor has a history of using document lures with pornographic themes to infect users and makes heavy use of USB shortcut techniques to spread the malware and infect additional targets. Attacks attributable to Aoqin Dragon typically drop one of two backdoors, Mongall and a modified version of the open source Heyoka project.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G1007

CrowdStrikenation-animal names

Aoqin Dragon

MandiantUNC uncategorised cluster

UNC94

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 13 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2010-3333 KEV8.57.80.97402010-11-10see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-38 / 1362%
SI-48 / 1362%
CM-26 / 1346%
CM-66 / 1346%
SI-76 / 1346%
CA-75 / 1338%
CM-75 / 1338%
AC-34 / 1331%
AC-44 / 1331%
SC-74 / 1331%
SI-104 / 1331%
SI-24 / 1331%
AC-63 / 1323%
SC-443 / 1323%
CM-82 / 1315%

Co-occurring actors

Similar actors

Overlapping CVEs

Active in same years

Same nation-state