CSIDB logo
Threat actor

Moshen Dragon

Attribution profile

Type
Spy
Location
China
Known incidents
2 incidents
First seen
2022-05-02
Last seen
2022-05-02
Updated
2026-07-31 23:32
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Moshen Dragon is a Chinese cyber‑espionage group tracked under that alias, with the actor’s location identified as China. The group focuses on telecommunications service providers in Central Asia, seeking to gather intelligence through extensive data exfiltration from compromised networks. Public reporting notes that the initial infection vector remains unknown, with analysis beginning at the point where the attackers abuse legitimate antivirus processes.

Their tactics involve sideloading malicious Windows DLLs into high‑privilege antivirus engines such as TrendMicro, Bitdefender, McAfee, Symantec and Kaspersky to gain unrestricted code execution and evade detection. Once inside, Moshen Dragon employs the Impacket framework for lateral movement, credential theft and capturing domain password change events, writing the harvested data to a temporary log file. The attackers deploy a passive loader that verifies the hostname against a hardcoded value before activating, indicating a unique loader per target system, and they use WinDivert to sniff network traffic until a decryption trigger is found, after which they unpack and launch payloads. The final stage consists of PlugX and ShadowPad backdoor variants, tools previously associated with multiple Chinese APT clusters, which are used to maintain persistence and exfiltrate information.

A representative operation occurred in May 2022 when Sentinel Labs reported Moshen Dragon’s activity against Asian telecom firms, detailing the abuse of antivirus products, Impacket‑based credential harvesting, and the deployment of customized loaders that only activate on verified hosts. The campaign demonstrated the group’s ability to adjust its approach based on the defenses encountered, employing packet‑sniffing techniques to stealthily decrypt and execute its payloads. This activity underscores the actor’s emphasis on covert, long‑term access to telecommunications infrastructure for espionage purposes.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB