← Back to all campaigns
ActiveMITRE ATT&CK

Night Dragon

Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.

First observedNov 1, 2009
Last observedFeb 1, 2011
Attributed actors0
Source-backed events2
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

No actor attribution is currently available.
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Last observed
Campaign

Night Dragon last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

Night Dragon first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Related vulnerabilities 0

No linked CVEs are available.

ATT&CK techniques 0

No linked techniques are available.

Malware and tools 0

No linked malware or tools are available.

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.