Also known as: G0017, BRONZE OVERBROOK, G0002, Shallow Taurus, Moafee
Threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. 2223 It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database