Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0002
MITRE ATT&CK Campaign · 2009–2011

Night Dragon (C0002)

ShareXLinkedInRedditHN

[Night Dragon](https://attack.mitre.org/campaigns/C0002) was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.(Citation: McAfee Night Dragon)

▪Techniques used (29)

T1078.002Domain AccountsT1608.001Upload MalwareT1588.001MalwareT1566.002Spearphishing LinkT1204.001Malicious LinkT1133External Remote ServicesT1005Data from Local SystemT1059.003Windows Command ShellT1027.002Software PackingT1190Exploit Public-Facing ApplicationT1078Valid AccountsT1027.013Encrypted/Encoded FileT1033System Owner/User DiscoveryT1588.002ToolT1112Modify RegistryT1003.002Security Account ManagerT1071.001Web ProtocolsT1114.001Local Email CollectionT1008Fallback ChannelsT1685Disable or Modify ToolsT1083File and Directory DiscoveryT1583.004ServerT1550.002Pass the HashT1219Remote Access ToolsT1110.002Password CrackingT1584.004ServerT1568Dynamic ResolutionT1105Ingress Tool TransferT1074.002Remote Data Staging

▪Software used (5)

S0008gsecdumptoolS0073ASPXSpymalwareS0350zwShellmalwareS0110attoolS0029PsExectool
C0002on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.