Dragonfly is a Russian state-aligned cyber espionage threat actor active since at least 2010 and widely tracked under aliases including Energetic Bear, Crouching Yeti, Berserk Bear, Dymalloy, Bromine, Koala Team, Dragonfly 2.0, Ghost Blizzard, Static Tundra, Temp.Isotope, TG-4192, Blue Kraken, Iron Liberty, and Operation Dragonfly. The group is best known for long-running intrusions against industrial and critical infrastructure environments, especially the energy sector, and for operations targeting industrial control system and SCADA-related networks, software vendors, and trusted third-party suppliers. Dragonfly has conducted multi-stage intrusion campaigns against organizations in energy, nuclear, water, aviation, government, and critical manufacturing. A defining characteristic of its tradecraft is strategic targeting of smaller or less secure suppliers and peripheral organizations as staging points to reach higher-value operational technology and enterprise victims. The actor has compromised ICS software providers and distributed trojanized legitimate software in supply-chain operations, while also using watering-hole compromises and spearphishing with malicious Microsoft Office attachments for initial access. The group has used malware including Havex, also known as Oldrea, and modified Karagany variants. Reported capabilities include credential theft, collection of Outlook and VPN-related data, screenshot capture, document inventorying, and remote access. In later campaigns associated with Dragonfly 2.0, the actor used PowerShell and batch scripting for execution and post-compromise activity, modified the Windows Registry including Run-key persistence, created scheduled tasks, created accounts, used web shells on exposed servers, harvested SMB/NTLM credentials through malicious documents, watering holes, and manipulated shortcut behavior, and leveraged remote access channels such as VPN, RDP, and Outlook Web Access. Post-compromise behavior has emphasized reconnaissance of enterprise and operational environments. Dragonfly operators have enumerated network trusts, zones, domains, users, and file servers; browsed files related to ICS and SCADA systems; and sought long-term access to critical infrastructure asset owners. The actor has also been linked to credential-harvesting watering-hole activity against aviation-related targets, including theft of Windows credentials from visitors to compromised websites. Cleanup and anti-forensic behavior has included deletion of tools, screenshots, and other operational artifacts after use. Dragonfly is assessed primarily as an espionage actor focused on intelligence collection and strategic access within critical infrastructure rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The alert directly connects them to reports of the Russian Federal Security Service's (FSB) Center 16 - aka Berserk Bear - accused of using a flaw (CVE-2018-0171) Cisco patched in 2018... The Cisco issue is with the Smart Install feature of Cisco IOS and IOS XE software, a CVSS 9.8 flaw, and one that many end-of-life-kit can't patch.
Exploit Public-Facing Application T1190 Conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.
Exploit Public-Facing Application T1190 Conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.
ALLANITE and DYMALLOY continued to target multiple United States (U.S.) industrial entities from September through October 2020. Operations included use of ZeroLogon to further intrusions into victim networks.
They have also exploited CVE-2018-0171 and CVE-2008-4128 in Cisco devices, both now listed in CISA’s Known Exploited Vulnerabilities catalog.
19 more CVEs tied to this actor tracked in Mallory.
113 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Mentioned only as an example actor in the detection annotation list.
Russian state-sponsored actors exploiting poorly configured and vulnerable networking devices, scanning for devices accepting default SNMP community strings, exfiltrating device configurations over TFTP, and exploiting Cisco vulnerabilities to gain deeper access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.