Skip to main content
QUIETLYTIC
Campaign

Night Dragon

Cyber espionage campaign targeting oil, energy, and petrochemical companies and executives in Kazakhstan, Taiwan, Greece, and the United States, collecting SCADA and production data, assessed as China-based.

Threat Level
HIGH
Status
Resolved
Targets
Oil, energy, and petrochemical companies and executives, Kazakhstan, Taiwan, Greece, United States

Overview

Night Dragon (MITRE ATT&CK ID C0002) was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives, in Kazakhstan, Taiwan, Greece, and the United States, per MITRE’s campaign profile. MITRE documents the unidentified threat actors as searching for information related to oil and gas field production systems, financials, and data collected from SCADA (supervisory control and data acquisition) systems. Based on observed techniques, tools, and network activity, MITRE’s citations note security researchers assessed the campaign involved a threat group based in China — one of the earlier documented instances of energy-sector-targeted espionage with an industrial-control-system data-collection angle.

Timeline

Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from November 2009 to February 2011 — one of the oldest campaigns in MITRE’s knowledge base by activity date.

Named actors and tools (per MITRE’s description vs. our relationship data)

MITRE’s description explicitly states the threat actors were “unidentified” beyond the China-based assessment. We confirmed this directly against MITRE’s raw published STIX bundle: every relationship object for this campaign is a technique/tool “uses” edge (gsecdump, ASPXSpy, zwShell, at, PsExec) — there is no “attributed-to” edge to any group, consistent with MITRE never having named a specific tracked actor for this campaign in the first place.

What we don’t have

No named threat group is formally attributed to this campaign in either MITRE’s description or our relationship data — only a general China-based assessment. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.

Frequently Asked Questions

What was Night Dragon? An early (2009-2011) cyber espionage campaign, per MITRE ATT&CK, targeting oil, energy, and petrochemical companies and executives across four countries, notable for its SCADA-system data-collection focus.

Who conducted Night Dragon? MITRE’s description states the actors were unidentified, with security researchers assessing a China-based origin based on observed techniques, tools, and network activity — not a confirmed named group.

What information did the attackers seek? Per MITRE’s documentation: oil and gas field production system data, company financials, and data collected from SCADA industrial control systems.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0002, aggregated August 31, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Analyst tools