VANADINITE is a Dragos-tracked industrial cyber activity group first identified in 2019 and focused primarily on initial access operations against industrial organizations. The group has targeted entities in the energy, manufacturing, and transportation sectors across North America, Europe, Australia, and Asia. Its operations center on exploiting vulnerabilities in external-facing services and network appliances, including VPN gateways, to gain entry into IT environments and establish a foothold that can support follow-on activity. VANADINITE has been assessed as pursuing information gathering, industrial control system compromise, and data theft in support of long-term strategic capability development. Reported tradecraft emphasizes initial access and foothold establishment via exposed perimeter infrastructure rather than publicly documented disruptive OT effects. The group is associated with targeting vulnerable external-facing appliances to access enterprise networks connected to industrial environments. A low-confidence assessment has linked VANADINITE to a ransomware incident affecting Taiwanese state-owned industrial control system companies, but that attribution is not sufficiently corroborated to characterize ransomware as a confirmed core activity. The available reporting supports viewing VANADINITE as an intrusion set focused on reconnaissance and access development against industrial targets, with objectives extending beyond opportunistic compromise toward sustained strategic positioning in industrial environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targets vulnerable external-facing network appliances to access IT networks and establish a foothold.
Targets vulnerable external-facing network appliances to access IT networks and establish a foothold.
ICS-focused information gathering and initial access activity group targeting industrial sectors globally, with emphasis on ICS compromise, data theft, and exploitation of recently disclosed remote access and VPN-related vulnerabilities.
Initial access-focused group targeting industrial organizations through exploitation of vulnerable external-facing services and network appliances, including VPN gateways.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.