CHRYSENE is a Dragos-tracked industrial intrusion activity group focused on cyber espionage and initial access against critical infrastructure owners and operators. The group has targeted industrial infrastructure organizations since at least early 2017, with victimology centered on manufacturing, petrochemical, oil and gas, and electric generation sectors. Its operations have been concentrated in Europe and the Middle East, with additional activity affecting North America, and its targeting expanded beyond an earlier focus on the Persian Gulf region. CHRYSENE is associated with intelligence-gathering operations against industrial enterprises, including organizations that own or operate operational technology environments. Reported tradecraft includes phishing, watering-hole attacks, malware deployment, covert communications, and PowerShell-based post-exploitation. The group has been linked to initial intrusions into industrial IT networks and reconnaissance intended to map environments and collect information relevant to future operations. Although CHRYSENE has not publicly demonstrated a confirmed disruptive or ICS-manipulation capability, its activity is consistent with staging, access development, and information collection that could support later attacks against OT asset owners and operators. CHRYSENE has been described as developing from an espionage campaign that drew attention in the aftermath of the 2012 Shamoon attack. Its known behavior aligns most strongly with strategic intelligence collection against industrial infrastructure rather than ransomware or overtly destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage-oriented activity group tied (by lineage) to campaigns around the 2012 Shamoon incident; targets petrochemical, oil & gas, and electric generation; active and evolving with targeting beyond the Gulf region.
Uses watering-hole attacks, malware, and covert communication for reconnaissance.
Uses watering-hole attacks, malware, and covert communication for reconnaissance.
Initial-intrusion-focused group targeting critical infrastructure and industrial organizations for IT compromise, reconnaissance, and victim acquisition, likely to support follow-on operations by other actors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.