Uptime Hamster: 20d 23h 34mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Operation Dragon Castling

Operation Dragon Castling

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
Operation Dragon Castling is a cyber-espionage campaign first publicly reported in March 2022, attributed with moderate confidence to a Chinese-speaking advanced persistent threat group. The group's primary motivation is information theft and espionage, specifically targeting betting and gambling-related companies in Southeast Asia. This group distinguishes itself through the exploitation of previously unknown vulnerabilities in widely used software, such as a zero-day in the WPS Office updater (CVE-2022-24934), to establish and maintain long-term persistent access for intelligence gathering. The group utilizes a robust, modular toolset, including a backdoor with code similarities to FFRat samples.

Actores similares

night-dragonactor · 1aoqin-dragonactor · 1sharp-dragon--chkptactor · 1Aoqin Dragonthreat-actor · 1Night Dragonapt · 1Amaranth-Dragonapt · 0Camaro Dragonapt · 0Moshen Dragonapt · 0dragonforceransomware · 580dragonransomwarethreat-actor · 2
Motivacion