Also known as: Havex
Executive Summary
Backdoor.Oldrea is a modular backdoor used by Dragonfly to target energy companies, distributed via supply chain compromise and including ICS-specific modules. The malware enables persistent access, data exfiltration, and command execution on compromised Windows systems. Its specialized modules pose a significant threat to energy sector security and integrity.
Enhanced Description
Backdoor.Oldrea, also known as Havex, is a sophisticated modular backdoor malware primarily used by the Dragonfly threat actor group to target energy companies since at least 2013. The malware's primary function is to establish a persistent backdoor on compromised Windows systems, enabling the attackers to execute commands, exfiltrate sensitive data, and install additional malicious modules. Notably, Backdoor.Oldrea was distributed via supply chain compromise, exploiting vulnerabilities in software used by the targeted energy sector. The malware includes specialized modules designed to enumerate and map Industrial Control Systems (ICS)-specific systems, processes, and protocols, demonstrating a tailored approach to disrupt and gather intelligence on critical infrastructure. This targeted approach highlights the significant threat posed by Backdoor.Oldrea to the security and integrity of energy sector operations.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the available data is moderate to high, based on historical reports from reputable sources such as Symantec and Gigamon. However, analysis gaps exist regarding the current activity and evolution of Backdoor.Oldrea, as well as the full scope of its technical capabilities.
Backdoor.Oldrea is a modular backdoor that used by Dragonfly against energy companies since at least 2013. Backdoor.Oldrea was distributed via supply chain compromise, and included specialized modules to enumerate and map ICS-specific systems, processes, and protocols.(Citation: Symantec Dragonfly)(Citation: Gigamon Berserk Bear October 2021)(Citation: Symantec Dragonfly Sept 2017)