DragonOK Updates Toolset and Targets Multiple Geographic Regions
ID: 8c5d2663-9680-422b-8920-c877e01af286
STIX ID: report--8c5d2663-9680-422b-8920-c877e01af286
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2017-02-23
Last Modified Date: 2017-02-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit42 reports DragonOK (an APT/threat actor) updated its toolset and conducted targeted campaigns across Japan, Taiwan, Tibet and Russia using phishing and RTF exploits (CVE-2015-1641) to deliver Sysget (v2–v4), IsSpace and newly observed TidePool malware; the blog provides technical analysis, network and file IOCs, decoy documents, and detection/mitigation guidance.
