Threat Actor

DragonOK

Also known as: DragonOK

[DragonOK](https://attack.mitre.org/groups/G0017) is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, [DragonOK](https://attack.mitre.org/groups/G0017) is thought to have a direct or indirect relationship with the threat group [Moafee](https://attack.mitre.org/groups/G0002). (Citation: Operation Quantum Entanglement) It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT. (Citation: New DragonOK)

2
Software

Properties

stix_id
intrusion-set--f3bdec95-3d62-42d9-a840-29630f6cdc1a
signal_observed_at
2026-09-11T17:55:00+00:00
type
intrusion-set

Software & Tools (2)

PlugX [malware]

[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Cita

PoisonIvy [malware]

[PoisonIvy](https://attack.mitre.org/software/S0012) is a popular remote access tool (RAT) that has been used by many groups.(Citation: FireEye Poison

Explore this actor's full graph with Ninja Signal

DragonOK — Threat Actor Profile — Ninja Signal | Ninja Signal