A Chinese-speaking threat actor was discovered by SentinelLabs threat analysts who were able to link it to malicious activity taking place in 2013. The hacking group called Aoqin Dragon focuses on espionage , targeting government, educational, and telecommunications organizations based in Singapore, Hong Kong, Vietnam, Cambodia, and Australia.

See also: Symbiote malware: Infects all running processes on Linux systems
Threat actor techniques have evolved over the years, but certain tactics and concepts remain unchanged.
Invasion and infection tactics
The Aoqin Dragon group has used three distinct infection chains since it was first detected, according to SentinelLabs. The earliest, used between 2012 and 2015, involves Microsoft Office that exploit known vulnerabilities such as CVE-2012-0158 and CVE-2010-3333.
This tactic was detected by FireEye in 2014 in a spear-phishing campaign coordinated by the Chinese-backed Naikon APT group ,targeting an APAC government entity and a US think tank.
The second infection method is to cover malicious executable files with fake anti-virus icons, tricking users into launching them and activating a malware dropper on devices .
See also: Massive Facebook phishing campaign generates millions
Since 2018, Aoqin Dragon has switched to using a removable disk shortcut file which, when clicked, performs DLL hijacking and loads an encrypted backdoor payload.
The malware runs under the name “Evernote Tray Application” and is executed at system startup. If the loader detects removable devices, it also copies the payload to infect other devices on the target’s network.

SentinelLabs identified two different backdoors used by this threat group, Mongall and a modified version of Heyoka. Both are DLLs that are loaded into memory, decrypted, and executed.
Aoqin Dragon managed to stay in the shadows for a decade, with only parts of its operation appearing in older reports [PDF] from cybersecurity firms.
The group achieved this by constantly evolving its techniques and changing tactics, something that will likely happen again after the exposure it received following the SentinelLabs report.
See also: Cuba ransomware: New variant detected in recent attacks
Considering that its activities align with the political interests of the Chinese government, it is almost certain that Aoqin Dragon will continue its cyberespionage operations, improving its evasion of detection and switching to new evasion tactics.
Information source: bleepingcomputer.com
