DragonOK__2014__fireeye-operation-quantum-entanglement.pdf
ID: e757c202-6ede-4929-bcd0-dec521884168
STIX ID: report--e757c202-6ede-4929-bcd0-dec521884168
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2014-09-10
Last Modified Date: 2014-09-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's Operation Quantum Entanglement analyzes two China-linked APT campaigns (Moafee and DragonOK) that share toolsets and TTPs — including custom RATs (CT/NewCT/NewCT2), Nflog, Mongall, PoisonIvy, Sysget/HelloBridge — and use HTRAN proxies and evasion techniques (CPU core checks, password‑protected documents, large null‑padded files); the report provides technical malware analysis, network beacon formats, decryption routines, IOCs and infrastructure attribution tying Moafee to Guangdong and DragonOK to Jiangsu provinces.
