EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/operation-night-dragon
377/430

File EL-0054CriticalResolvedEspionage Operation / Critical Infrastructure Targeting

Operation Night Dragon

Also filed as Night Dragon · China Cyber Espionage Campaign

Operation Night Dragon was a sophisticated, long-term cyber espionage campaign targeting critical energy infrastructure globally. The campaign focused on exfiltrating proprietary industrial control system (ICS) data, operational technology (OT) blueprints, and intellectual property from major energy corporations. Its primary goal was to provide China with strategic technological advantages in the global energy market.

  • #china
  • #cyber-espionage
  • #energy-sector
  • #apt
  • #industrial-control-systems
  • #ics
Notoriety7/10
Event
1 Jan 2010
Disclosed
1 Jun 2011
Target
Energy Companies
Actor
China-linked Actor
Scale
Estimated multiple terabytes of technical schematics and operational data
Status
Resolved

01Summary

The operation was characterized by persistent, low-profile infiltration into the networks of major oil and gas companies, particularly those operating advanced industrial facilities. Attackers utilized custom malware and zero-day exploits to establish deep persistence within the victim's Operational Technology (OT) networks, bypassing traditional IT security measures. The exfiltrated data included detailed schematics of pipelines, refinery processes, and SCADA system configurations. The campaign demonstrated a high level of technical sophistication, suggesting state-level resources dedicated to long-term intelligence gathering rather than immediate disruption. The disclosure of the operation highlighted the vulnerability of critical infrastructure to foreign state-sponsored cyber threats.

02Background

The early 2010s saw a marked increase in state-sponsored cyber espionage, particularly targeting Western industrial and military secrets. China's growing economic and military ambitions necessitated advanced intelligence gathering capabilities, making the energy sector a prime target for technological acquisition. This period marked a shift from simple data theft to deep, persistent network infiltration.

03Key revelations

  1. 01The existence of a coordinated, long-term state effort to map and steal global energy infrastructure blueprints.
  2. 02The vulnerability of critical national infrastructure (CNI) to non-disruptive, intelligence-gathering cyber attacks.
  3. 03The successful bypassing of air-gapped or highly segmented OT networks.

04Technical analysis

The attackers employed custom malware designed specifically for industrial environments, often targeting protocols like Modbus and DNP3. Initial access was frequently achieved through spear-phishing campaigns targeting high-value employees or through supply chain compromises involving third-party maintenance vendors. The malware was designed to map the internal network topology and identify key SCADA/DCS controllers before initiating data staging and exfiltration.

Attack vector
Spear-phishing and Supply Chain Compromise
Attack method
Persistent Espionage and Data Exfiltration
Initial access
Phishing/Compromised Vendor Access
Lateral movement
Network Mapping and Protocol Exploitation
Persistence
Backdoors and Scheduled Tasks within OT systems
Exfiltration
Encrypted Channels via compromised VPNs or dedicated exfiltration servers
Tool / malware
Custom ICS Malware (Specific names often classified or proprietary)
Malware family
ICS/SCADA Stealers
Malware type
Spyware/Stealer

Vulnerabilities exploited

  • Zero-day vulnerabilities in industrial protocols
  • Weak network segmentation between IT and OT networks

MITRE ATT&CK techniques

  • T1078 (Valid Accounts)
  • T1021 (Remote Services)
  • T1562.001 (Impair Defenses: Registry)

05Threat actor

The actors associated with Night Dragon are believed to be highly skilled, state-sponsored units, likely linked to the PLA. Their operational profile emphasizes stealth, deep persistence, and a focus on non-disruptive intelligence gathering, making them difficult to detect and attribute.

Aliases

  • APT1
  • PLA Unit 61398
  • China National Intelligence

APT designations

  • APT1

MITRE groups

  • T0003
  • T1021

Attribution sources

  • Mandiant
  • FireEye
  • Cybersecurity Research Firms

06Victims and impact

Additional victims

  • Industrial Control System Vendors
  • Foreign Government Energy Agencies

Countries affected

  • United States
  • Europe
  • Middle East

07Data exposed

Data types

  • Industrial Control System Blueprints
  • Operational Technology (OT) Data
  • Proprietary Engineering Schematics
  • Employee Credentials

Notable documents

  • SCADA System Schematics
  • Refinery Process Flow Diagrams
  • Pipeline Control Logic

08Financial damage

Damage estimate is based on lost competitive advantage and intellectual property theft, not immediate financial loss.

09Timeline

  1. 2009-01-01Start of persistent infiltration into target networks.
  2. 2011-06-01Discovery and public disclosure of the espionage campaign.

10Reaction and fallout

Public reaction

The incident spurred significant global debate regarding the necessity of international cyber norms and the protection of critical infrastructure. Governments and industry leaders increased funding for OT security measures.

Political impact

It accelerated the adoption of stricter national cybersecurity policies, particularly in Western nations, leading to increased cooperation between private industry and government intelligence agencies.

Geopolitical consequences

The operation reinforced the concept of cyber warfare as a primary tool of state competition, escalating tensions between major global powers regarding technological supremacy.

11Legal

No specific international legal action was taken, but the incident contributed to the development of national cyber defense legislation (e.g., NIS Directive in the EU).

Civil lawsuits

  • Increased litigation regarding supply chain security and vendor vetting.

12Aftermath

Policy changes

  • Mandatory network segmentation between IT and OT environments.
  • Adoption of 'Security by Design' principles for industrial control systems.

Regulatory changes

  • Stricter international standards for critical infrastructure protection (e.g., IEC 62443).

Security improvements

  • Implementation of unidirectional gateways (data diodes) in critical control loops.
  • Enhanced monitoring and behavioral analytics specifically for industrial protocols.

13Significance and legacy

Significance

Operation Night Dragon is a foundational case study in state-sponsored cyber espionage targeting industrial control systems. It demonstrated that the most valuable secrets are not just financial records, but the operational blueprints of global infrastructure, setting a precedent for 'cyber-physical' warfare.

Legacy

The incident permanently elevated the security focus on Operational Technology (OT) networks, forcing energy and industrial sectors to treat their control systems with the same level of security rigor previously reserved for military assets. It also fueled the growth of specialized ICS security firms.

14Disclosure and media

Authentication
Technical forensic analysis of malware and network logs

Media partners

  • The Guardian
  • Reuters
  • Industry Security Blogs

Publishing organisations

  • Mandiant
  • FireEye

15Related files

Related events

  • APT1 activity
  • China's cyber espionage campaigns

Went on to inspire

  • TRITON/TRISIS (Industrial Sabotage)
  • Stuxnet (ICS Targeting)

16Field notes

  1. 01The attackers' focus on OT data meant that simple IT security measures (like firewalls) were often insufficient to detect the intrusion.
  2. 02The campaign's longevity suggests a high level of patience and sustained funding from the sponsoring state.

17Resolution

The threat was mitigated through a combination of network segmentation, vendor risk management, and the deployment of specialized ICS monitoring tools.

18Sources

Official documents

  • Mandiant Threat Reports (2011)

References

  1. [1]Mandiant Threat Intelligence Reports
  2. [2]Industry Cybersecurity Advisories
Fact sheetEL-0054

Dates

Event
1 Jan 2010
Started
1 Jan 2009
Ended
31 Dec 2011
Discovered
1 Jun 2011
Disclosed
1 Jun 2011
Ongoing
No

Target

Organisation
Energy Companies
Type
Corporation
Sector
Energy/Oil & Gas
Country
Global

Actor

Name
China-linked Actor
Type
Nation-State Actor
Nationality
Chinese
Nation-state
China
Affiliation
People's Liberation Army (PLA)
Motivation
Acquisition of intellectual property, military technology, and strategic industrial control system data related to foreign energy infrastructure.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Estimated multiple terabytes of technical schematics and operational data
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.