logo

DragonOK__2014__fireeye-operation-quantum-entanglement.pdf

ID: e757c202-6ede-4929-bcd0-dec521884168

STIX ID: report--e757c202-6ede-4929-bcd0-dec521884168

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2014-09-10

Last Modified Date: 2014-09-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's Operation Quantum Entanglement analyzes two China-linked APT campaigns (Moafee and DragonOK) that share toolsets and TTPs — including custom RATs (CT/NewCT/NewCT2), Nflog, Mongall, PoisonIvy, Sysget/HelloBridge — and use HTRAN proxies and evasion techniques (CPU core checks, password‑protected documents, large null‑padded files); the report provides technical malware analysis, network beacon formats, decryption routines, IOCs and infrastructure attribution tying Moafee to Guangdong and DragonOK to Jiangsu provinces.