Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Dragonfly

Also known as: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE, Dragonfly, Group 24, Koala Team, Anger Bear, Havex, PEACEPIPE, Fertger, ALLANITE, CASTLE, G0035, ATK6, ITG15, Blue Kraken, TeamSpy, Team Bear, IRON LYRIC, Palmetto Fusion, two separate groups, tracked as, Backdoor.Oldrea, Temp, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Koala, Sandworm Team

Description

Dragonfly is a highly sophisticated cyber espionage group that has operated for more than a decade, targeting high‑value organizations across the globe, with a particular focus on industrial control systems and critical infrastructure. Attributed to Russia’s Federal Security Service (FSB) Center 16, its tactics combine supply‑chain compromise, watering‑hole attacks, spear‑phishing, and exploit kits to gain initial access and establish persistence. The actor exploits trojanized software bundles distributed through legitimate industrial‑control-system vendors, while also deploying redirect‑iframe watering holes that serve Hello exploit kit payloads. Once inside it leverages remote and local administration tools—most notably the Backdoor.Oldrea RAT (Havex) and Trojan.Karagany—to extend its foothold, gather credentials, and exfiltrate sensitive data. Dragonfly’s methodology is emblematic of modern state‑backed threat actors: it uses open‑source automation scripts written in Python and Windows command shell for operational efficiency, scans for vulnerable systems with reconnaissance tools (e.g., Nmap, Sublist3r), and hides its activity through legitimate web infrastructure and file‑system persistence mechanisms such as .LNK manipulation. The resulting attacks have repeatedly crippled energy utilities, government networks and aviation operators. Collectively, Dragonfly’s campaigns illustrate a deliberate effort to exfiltrate vast amounts of intelligence from critical sectors while maintaining operational stealth for prolonged periods.

TTP Summary

Active

Goals & Targeting

Targeted Sectors

Energy
Technology
Education
Critical infrastructure
Defense
Healthcare
Government
Manufacturing
Critical infrastructure
Financial services
Aviation
Telecommunications
Pharmaceutical
Transportation
Oil gas
Nuclear
Construction
Information technology
Chemical
Maritime
Think tank
Aerospace
Utilities
Media
Hospitality
Non profit
Legal services

Targeted Countries / Regions

middle_east
europe
US
UA
CN
GB
IN
JP
CA
RU
AU
KR
PL
SG
VN
TW
IR
DE
KZ
IL
TR
FR
BR
MX
ES
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

Dragonfly is a Russian state-sponsored threat actor, attributed to the FSB Center 16, that has been active since at least 2010. It specializes in supply‑chain and watering‑hole attacks against critical infrastructure, especially energy, defense, aviation and government organizations, and it frequently uses spear‑phishing with malicious PDFs and the Hello exploit kit to deliver malware. Dragonfly’s operations result in persistence through RATs such as Backdoor.Oldrea (Havex) and extensive data exfiltration from compromised servers.

Goals & Targeting

The strategic objectives of Dragonfly appear to center on long‑term intelligence gathering rather than direct sabotage. By compromising defense contractors, aviation firms and national grid operators, the group seeks privileged access to proprietary designs, technical schematics and policy documents that are valuable in geopolitical or economic contexts. Its targeted infiltration of government networks further suggests a desire to siphon classified information that could influence international power dynamics.

Enhanced Description

Key Capabilities

  • Uses Python scripts to automate operations
  • Watering‑hole attacks via redirect iframes
  • Spear‑phishing with malicious PDF attachments
  • Deploys Hello exploit kit for initial compromise
  • Supply‑chain attacks using trojanized software bundles from industrial control vendors
  • Targets government and aviation networks
  • Exfiltrates data from compromised servers

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control
Defense Evasion
Impact

ATT&CK Techniques

T1053.005
T1113
T1033
T1133
T1003.002
T1074.001
T1110.002
T1003.004
T1087.002
T1204.002
T1069.002
T1598.003
T1566.001
T1608.004
T1135
T1005
T1098.007
T1190
T1583.001
T1560
T1595.002
T1112
T1505.003
T1136.001
T1591.002
T1016
T1059
T1685.005
T1583.003
T1083
T1564.002
T1071.002
T1210
T1547.001
T1588.002
T1110
T1078
T1114.002
T1187
T1195.002
T1203
T1012
T1059.006
T1059.003
T1036.010
T1070.004
T1189
T1221
T1584.004
T1018
T1105
T1021.001
T1003.003
T1686

Software / Tooling

Backdoor.Oldrea
Havex RAT
Trojan.Karagany
Hello exploit kit
Pikabot
LightsOut ExploitKit

Campaigns & Victims

Dragonfly exhibits a consistent, low‑profile operational tempo, striking once or twice per year and then retreating to maintain stealth while exfiltrating data at scale. Victim profiles skew towards critical infrastructure—energy utilities, defense contractors, aviation firms—and governmental agencies that provide strategic information. Notable campaigns include the 2017–2018 attacks on Western energy suppliers, the 2020 “Berserk Bear” phishing campaign against U.S. industry, and a series of supply‑chain compromises in late 2020 targeting SCADA software distributors.

IOC Patterns

  • malicious PDF attachment
  • redirect iframe injection
  • exploit kit Hello
  • trojanized software bundle
  • compromised download site
  • data exfiltration from victim servers

Recommended Actions

  • Verify authenticity of downloaded software via hash checks or trusted code signing
  • Implement web filtering to block known compromised distribution sites and redirect iframes
  • Deploy IDS/IPS to monitor anomalous data transfer indicative of exfiltration
  • Maintain up‑to‑date threat intelligence on supply‑chain attack vectors
  • Provide user awareness training focused on spear‑phishing and malicious PDF attachments

Suggested Tags

APT
Russian state‑sponsored
Energy sector
Critical infrastructure
Watering‑hole attack
Spear phishing
Supply-chain attack
Trojanized software
Data exfiltration

Confidence Assessment

Confidence in the attribution of Dragonfly to a Russian state actor and its general tactics (supply‑chain, watering‑hole, spear‑phishing) is high due to multiple independent reports. However, specific details about newer operations, persistence mechanisms beyond known RATs, and precise timelines exhibit moderate uncertainty. Future intelligence collection should focus on corroborating recent supply‑chain artifacts and validating new attack vectors reported in the last 12 months.

ATT&CK Techniques

Collection
5 techniques
Credential Access
6 techniques
Discovery
8 techniques
Execution
7 techniques
Initial Access
4 techniques
Persistence
5 techniques
Stealth
5 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 1 Domain 12 URL 7

References

  1. CISA AA20-296A Berserk Bear December 2020 — CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.
  2. DOJ Russia Targeting Critical Infrastructure March 2022 — Department of Justice. (2022, March 24). Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide. Retrieved April 5, 2022.
  3. Dragos DYMALLOY — Dragos. (n.d.). DYMALLOY. Retrieved August 20, 2020.
  4. Fortune Dragonfly 2.0 Sept 2017 — Hackett, R. (2017, September 6). Hackers Have Penetrated Energy Grid, Symantec Warns. Retrieved June 6, 2018.
  5. Mandiant Ukraine Cyber Threats January 2022 — Hultquist, J. (2022, January 20). Anticipating Cyber Threats as the Ukraine Crisis Escalates. Retrieved January 24, 2022.
  6. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  7. Secureworks MCMD July 2019 — Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.
  8. Secureworks IRON LIBERTY July 2019 — Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.
  9. Secureworks Karagany July 2019 — Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.
  10. Gigamon Berserk Bear October 2021 — Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.
  11. Symantec Dragonfly Sept 2017 — Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.
  12. Symantec Dragonfly — Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.
  13. Symantec Dragonfly 2.0 October 2017 — Symantec. (2017, October 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved April 19, 2022.
  14. UK GOV FSB Factsheet April 2022 — UK Gov. (2022, April 5). Russia's FSB malign activity: factsheet. Retrieved April 5, 2022.
  15. apt.etda.or.th — Cited by web research for: two separate groups
  16. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  17. attack.mitre.org — Cited by web research for: OilRig
  18. apt.etda.or.th — Cited by web research for: Industroyer
  19. https://www.symantec.com/blogs/threat-intelligence/dragonfly-energy-sector-cyber-attacks — Cited by AI analysis.
  20. https://blog.talosintelligence.com/2017/07/template-injection.html — Cited by AI analysis.
  21. https://www.us-cert.gov/ncas/alerts/TA18-074A — Cited by AI analysis.
  22. https://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/Dragonfly_Threat_Against_Western_Energy_Suppliers.pdf — Cited by AI analysis.
  23. https://us-cert.cisa.gov/ncas/alerts/aa20-296a — Cited by AI analysis.
  24. https://www.kaspersky.com/resource-center/threats/crouching-yeti-energetic-bear-malware-threat — Cited by AI analysis.
  25. https://www.sans.org/reading-room/whitepapers/ICS/impact-dragonfly-malware-industrial-control-systems-36672 — Cited by AI analysis.
  26. https://exchange.xforce.ibmcloud.com/threat-group/388909715625410bd48078d0ddbc29c4 — Cited by AI analysis.

Intel Summary

58

Techniques

59

Tools

0

Campaigns

115

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
Supply Chain Attack
Phishing
Government Targeting
espionage
FSB-linked
critical Infrastructure
Russian state‑sponsored
Energy sector
Critical infrastructure
Watering‑hole attack
Spear phishing
Supply-chain attack
Trojanized software
Data exfiltration

Details

MITRE ID
G0035
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--1c63d4ec-0a75-4daa-b1df-0d11af3d3cc1
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.