logo

DragonOK Updates Toolset and Targets Multiple Geographic Regions

ID: 8c5d2663-9680-422b-8920-c877e01af286

STIX ID: report--8c5d2663-9680-422b-8920-c877e01af286

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2017-02-23

Last Modified Date: 2017-02-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit42 reports DragonOK (an APT/threat actor) updated its toolset and conducted targeted campaigns across Japan, Taiwan, Tibet and Russia using phishing and RTF exploits (CVE-2015-1641) to deliver Sysget (v2–v4), IsSpace and newly observed TidePool malware; the blog provides technical analysis, network and file IOCs, decoy documents, and detection/mitigation guidance.