Overview
Night Dragon (MITRE ATT&CK ID C0002) was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives, in Kazakhstan, Taiwan, Greece, and the United States, per MITRE’s campaign profile. MITRE documents the unidentified threat actors as searching for information related to oil and gas field production systems, financials, and data collected from SCADA (supervisory control and data acquisition) systems. Based on observed techniques, tools, and network activity, MITRE’s citations note security researchers assessed the campaign involved a threat group based in China — one of the earlier documented instances of energy-sector-targeted espionage with an industrial-control-system data-collection angle.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from November 2009 to February 2011 — one of the oldest campaigns in MITRE’s knowledge base by activity date.
Named actors and tools (per MITRE’s description vs. our relationship data)
MITRE’s description explicitly states the threat actors were “unidentified” beyond the China-based assessment. We confirmed this directly against MITRE’s raw published STIX bundle: every relationship object for this campaign is a technique/tool “uses” edge (gsecdump, ASPXSpy, zwShell, at, PsExec) — there is no “attributed-to” edge to any group, consistent with MITRE never having named a specific tracked actor for this campaign in the first place.
What we don’t have
No named threat group is formally attributed to this campaign in either MITRE’s description or our relationship data — only a general China-based assessment. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What was Night Dragon? An early (2009-2011) cyber espionage campaign, per MITRE ATT&CK, targeting oil, energy, and petrochemical companies and executives across four countries, notable for its SCADA-system data-collection focus.
Who conducted Night Dragon? MITRE’s description states the actors were unidentified, with security researchers assessing a China-based origin based on observed techniques, tools, and network activity — not a confirmed named group.
What information did the attackers seek? Per MITRE’s documentation: oil and gas field production system data, company financials, and data collected from SCADA industrial control systems.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0002, aggregated August 31, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.