CHRYSENE is an Iranian-linked cyberespionage activity group targeting industrial infrastructure organizations, including manufacturing, petrochemical, oil and gas, and electric generation enterprises. Active against industrial organizations since at least early 2017, it initially focused on the Persian Gulf and subsequently expanded its targeting across the Middle East, Europe, and North America. The group focuses on initial compromise of enterprise IT networks and intelligence gathering against operational technology asset owners and operators. Its techniques include phishing with IT-themed lures, watering-hole attacks, malware deployment, covert communications, and PowerShell-based post-exploitation. CHRYSENE has continued developing malware and introducing additional tools to support industrial-network intrusions and reconnaissance. Although its victimology includes organizations operating industrial control systems, CHRYSENE has not demonstrated an OT-specific capability to manipulate industrial processes or cause physical disruption. Its activity is principally associated with espionage and access development rather than demonstrated destructive industrial attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as part of Iran's concentrated OT/ICS threat capability. The named passage does not provide a separately attributable intrusion, malware family, or exploited vulnerability.
Espionage-oriented activity group tied (by lineage) to campaigns around the 2012 Shamoon incident; targets petrochemical, oil & gas, and electric generation; active and evolving with targeting beyond the Gulf region.
Uses watering-hole attacks, malware, and covert communication for reconnaissance.
Uses watering-hole attacks, malware, and covert communication for reconnaissance.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.