Also known as: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE, Dragonfly, Group 24, Koala Team, Anger Bear, Havex, PEACEPIPE, Fertger, ALLANITE, CASTLE, G0035, ATK6, ITG15, Blue Kraken, TeamSpy, Team Bear, IRON LYRIC, Palmetto Fusion, two separate groups, tracked as, Backdoor.Oldrea, Temp, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Koala, Sandworm Team
Dragonfly is a highly sophisticated cyber espionage group that has operated for more than a decade, targeting high‑value organizations across the globe, with a particular focus on industrial control systems and critical infrastructure. Attributed to Russia’s Federal Security Service (FSB) Center 16, its tactics combine supply‑chain compromise, watering‑hole attacks, spear‑phishing, and exploit kits to gain initial access and establish persistence. The actor exploits trojanized software bundles distributed through legitimate industrial‑control-system vendors, while also deploying redirect‑iframe watering holes that serve Hello exploit kit payloads. Once inside it leverages remote and local administration tools—most notably the Backdoor.Oldrea RAT (Havex) and Trojan.Karagany—to extend its foothold, gather credentials, and exfiltrate sensitive data. Dragonfly’s methodology is emblematic of modern state‑backed threat actors: it uses open‑source automation scripts written in Python and Windows command shell for operational efficiency, scans for vulnerable systems with reconnaissance tools (e.g., Nmap, Sublist3r), and hides its activity through legitimate web infrastructure and file‑system persistence mechanisms such as .LNK manipulation. The resulting attacks have repeatedly crippled energy utilities, government networks and aviation operators. Collectively, Dragonfly’s campaigns illustrate a deliberate effort to exfiltrate vast amounts of intelligence from critical sectors while maintaining operational stealth for prolonged periods.
Active
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Dragonfly is a Russian state-sponsored threat actor, attributed to the FSB Center 16, that has been active since at least 2010. It specializes in supply‑chain and watering‑hole attacks against critical infrastructure, especially energy, defense, aviation and government organizations, and it frequently uses spear‑phishing with malicious PDFs and the Hello exploit kit to deliver malware. Dragonfly’s operations result in persistence through RATs such as Backdoor.Oldrea (Havex) and extensive data exfiltration from compromised servers.
Goals & Targeting
The strategic objectives of Dragonfly appear to center on long‑term intelligence gathering rather than direct sabotage. By compromising defense contractors, aviation firms and national grid operators, the group seeks privileged access to proprietary designs, technical schematics and policy documents that are valuable in geopolitical or economic contexts. Its targeted infiltration of government networks further suggests a desire to siphon classified information that could influence international power dynamics.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Dragonfly exhibits a consistent, low‑profile operational tempo, striking once or twice per year and then retreating to maintain stealth while exfiltrating data at scale. Victim profiles skew towards critical infrastructure—energy utilities, defense contractors, aviation firms—and governmental agencies that provide strategic information. Notable campaigns include the 2017–2018 attacks on Western energy suppliers, the 2020 “Berserk Bear” phishing campaign against U.S. industry, and a series of supply‑chain compromises in late 2020 targeting SCADA software distributors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the attribution of Dragonfly to a Russian state actor and its general tactics (supply‑chain, watering‑hole, spear‑phishing) is high due to multiple independent reports. However, specific details about newer operations, persistence mechanisms beyond known RATs, and precise timelines exhibit moderate uncertainty. Future intelligence collection should focus on corroborating recent supply‑chain artifacts and validating new attack vectors reported in the last 12 months.
No campaigns linked yet.
No observed data linked yet.
58
Techniques
59
Tools
0
Campaigns
115
IOCs
0
Observed Data
13
Tactics