Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Threat Actors
/
Night Dragon
Threat Actor
๐จ๐ณ
China
Night Dragon
Also known as:
G0014
Indicators of Compromise
6
Domain
110gongan[.]com
Filename
Chinese Dragon
Filename
ไธญๅฝ้พ.zip
GitHub Repo
SQLRCE0
GitHub Repo
Yx Technology
IP
207[.]56[.]30[.]188
MITRE ATT&CK TTPs
6
T1003
OS Credential Dumping
Credential Access
T1059
Command and Scripting Interpreter
Execution
T1071.001
Web Protocols
Command And Control
T1133
External Remote Services
Persistence
T1212
Exploitation for Credential Access
Credential Access
T1484.001
Group Policy Modification
Defense Evasion
Source Articles
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
The source code for the Flying Eagle Android remote access trojan (RAT) is circulating in criminal Telegram channels, enabling widespread deployment of the malware. Researchers identified infrastructure linked to 170 servers hosting control panels or certificates associated with the RAT, which is used in a fake Chinese Public Security app called 'ๅ ฌๅฎไธ็ฝ้ๅ'. The malware can steal payment credentials, record screens, access cameras, and perform phishing attacks on financial and government apps. A second Android RAT, Night Dragon, was introduced by one of the same Telegram groups, though it appears to be a separate build with no shared code with Flying Eagle.
hacker-news
ยท
4h ago