Netskope Threat Labs

Mongall

ATP Sandbox Adv. Heuristics

Mongall is a backdoor that has been in use since at least 2013, including by the Aoqin Dragon threat actor in campaigns against organizations in Southeast Asia and Australia.

First seen
June 2022
Last seen
October 2026

15 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1082System Information Discovery
  • T1120Peripheral Device Discovery
  • T1680Local Storage Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
Win32.Backdoor.Mongall
Win32.Trojan.Mongall