← Threat Actors / China / Camaro Dragon
DOSSIER // CAMARO-DRAGON

Camaro Dragon

▲ High Threat China
Primary Aliases: DEV-0117 Mustang Panda Twill Typhoon UNC6384
Confidence Rating 70% (Grounded)

In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of tools mentioned in the Avast report in late 2022. The incident was attributed to Camaro Dragon, a Chinese-based espionage threat actor whose activities overlap with activities tracked by different researchers as Mustang Panda and LuminousMoth, whose focus is primarily on Southeast Asian countries and their close peers.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (85 TTPs)

📥 Download Navigator JSON
Operational Techniques 50
T1000 Upload Malware
↗
T1000 Web Services
↗
T1000 Windows Management Instrumentation
↗
T1000 Symmetric Cryptography
↗
T1000 Search Open Websites/Domains
↗
T1000 Malicious Link
↗
T1000 Deobfuscate/Decode Files or Information
↗
T1000 Visual Basic
↗
T1000 IDE Tunneling
↗
T1000 Domain Account
↗
T1000 Hidden Files and Directories
↗
T1000 Mshta
↗
T1000 Dynamic API Resolution
↗
T1000 Email Accounts
↗
T1000 DCSync
↗
T1000 InstallUtil
↗
T1000 Archive via Utility
↗
T1000 Domain Groups
↗
T1000 Protocol or Service Impersonation
↗
T1000 Software Deployment Tools
↗
T1000 Adversary-in-the-Middle
↗
T1000 IDE Extensions
↗
T1000 Replication Through Removable Media
↗
T1000 LSASS Memory
↗
T1000 Tool
↗
T1000 Digital Certificates
↗
T1000 Archive via Custom Method
↗
T1000 File Deletion
↗
T1000 Shared Modules
↗
T1000 Non-Application Layer Protocol
↗
T1000 Executable Installer File Permissions Weakness
↗
T1000 Stage Capabilities
↗
T1000 Debugger Evasion
↗
T1000 Domains
↗
T1000 DLL
↗
T1000 Windows Management Instrumentation Event Subscription
↗
T1000 Native API
↗
T1000 NTDS
↗
T1000 Obfuscated Files or Information
↗
T1000 JavaScript
↗
T1000 Junk Code Insertion
↗
T1000 Malicious File
↗
T1000 Protocol Tunneling
↗
T1000 Masquerade File Type
↗
T1000 Double File Extension
↗
T1000 Web Service
↗
T1000 Traffic Signaling
↗
T1000 Match Legitimate Resource Name or Location
↗
T1000 Malware
↗
T1000 LNK Icon Smuggling
↗
Copied to clipboard

LINK COPIED TO CLIPBOARD