China-Linked DragonOK APT Group continues updating tools and tactics
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-1641 | Memory Corruption RCE in Microsoft Office via Malicious RTF Files Microsoft Office contains a memory corruption flaw (CWE-399) in its handling of Rich Text Format (RTF) files, allowing a crafted RTF document to corrupt memory when the file is parsed. The flaw is triggered by opening a specially crafted RTF file — typically delivered as an email attachment — in an affected version of Microsoft Office. Successful exploitation yields remote code execution in the context of the current user, so attacker privilege is limited to the rights of the logged-in account. Per the CISA data, Microsoft Office is the affected product, with no specific version ranges provided; the flaw was fixed in Microsoft's April 2015 Patch Tuesday security updates (MS15-033), so risk is concentrated on systems that never applied those updates. Exploitation is confirmed in the wild — the CVE was added to the CISA KEV on 2021-11-03 (ransomware use unknown) — it carries a 96.8% EPSS probability of exploitation within 30 days (100th percentile), and related reporting links RTF exploit techniques of this era to targeted APT campaigns (e.g., the T9000 backdoor and DragonOK tooling). Do: Apply Microsoft's April 2015 Office security updates (MS15-033) on all endpoints, per the CISA KEV required action, prioritizing hosts running older Office editions, and verify installation via installed-updates checks. As interim hardening, treat inbound RTF files with suspicion (block or sandbox RTF email attachments) and monitor for suspicious child processes spawned by Word (e.g., Winword.exe launching cmd.exe or PowerShell) to detect possible prior exploitation. Organizations still on legacy Office versions should upgrade to currently supported editions that receive ongoing security updates. | — | 97% | KEV |
| masshundreds of millions of Office installations potentially affected (unpatched subset unknown) |
Full article499 words · extracted from securityaffairs.com · click to collapse

The China-linked DragonOK continues updating tools and tactics and targeted entities in various countries, including Russia and Tibet.
It was September 2014, when security researchers at FireEye spotted for the first time the cyber espionage activities of a Chinese state-sponsored group dubbed DragonOK.
At the time, FireEye discovered two hacking campaigns conducted by distinct groups operating in separate regions of China that seem to work in parallel.
The first team of hackers named Moafee, targeted military and government organizations which were in some way involved in South China sea dispute. The attackers hit different organizations as explained by the researchers at FireEye in a blog post, and appears to operate from the Guangdong Province and hit entities working in the defense industry in the United States.
The second team, dubbed DragonOK, conducted corporate espionage operations on high-tech and manufacturing companies in Japan and Taiwan.
DragonOK is back and recently targeted Japanese organizations in several industries, including manufacturing, technology, energy, higher education and semiconductor.
While Japan is considered the main target of the APT, hackers also targeted individuals or organizations in Taiwan, Tibet, and Russia.
According to the experts at Palo Alto Networks, one of the malware used by the DragonOK APT was dubbed Sysget and was used to target entities in Taiwan.
The Sysget malware was delivered both directly via phishing emails, as well as in RTF documents triggering the CVE-2015-1641 flaw that in turn leveraged a unique shellcode. The experts observed three distinct new versions of Sysget malware that were improved to make harder the detection and the analysis by security solutions.
PaloAlto also observed DragonOK hackers using other two families malware, the IsSpace and TidePool.

“IsSpace” is an evolution of the NFlog backdoor used by both DragonOK and Moafee. The second malware TidePool was observed earlier this year in targeted attacks powered by a different Chinese APT group, dubbed Operation Ke3chang.
Back in 2013, the security researchers at FireEye spotted a group of China-Linked hackers that conducted an espionage campaign on foreign affairs ministries in Europe. The campaign was named ‘Operation Ke3chang,’ the same threat actors were spotted targeting personnel at Indian embassies across the world earlier this year.
DragonOK now used the TidePool malware in targeted attacks against organizations in Russia and Tibet.
The analysis published by Palo Alto Networks researchers included links between the C&C domains of the various malware used by the DragonOK (i.e. TidePool, IsSpace and Sysget), and other Indicators of Compromise.
“The DragonOK group are quite active and continue updating their tools and tactics. Their toolset is being actively developed to make detection and analysis more difficult. Additionally, they appear to be using additional malware toolsets such as TidePool.” states Palo Alto Networks. “While Japan is still the most-targeted region by this group, they look to be seeking out victims in other regions as well, such as Taiwan, Tibet, and Russia.”
Enjoy the report!
[adrotate banner=”9″]
(Security Affairs – DragonOK, China)
[adrotate banner=”12″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/55113/apt/china-linked-dragonok.html