Havex, also known as Backdoor.Oldrea and Energetic Bear RAT, is a Windows remote access trojan associated with the Dragonfly/Energetic Bear intrusion set and long-running espionage operations against industrial and energy-sector targets. It was notably used in campaigns against industrial control system and SCADA environments, including through compromises of ICS software vendors and trojanized legitimate software updates, as well as phishing and watering-hole activity. Public U.S. government reporting later attributed Havex activity to Russian state-linked actors, and U.S. indictments tied the broader Dragonfly/Havex campaign to officers of FSB Center 16.
Havex functions as a command-and-control-enabled backdoor that profiles infected hosts and their surrounding networks, then transmits collected information to attacker-controlled infrastructure. Reported host reconnaissance includes collection of running processes, the current username, and network adapter configuration. Some samples also included a publicly available browser password recovery utility, indicating credential theft capability against browser-stored secrets. Havex can enumerate network resources and scan for additional systems of interest, supporting follow-on intrusion activity in enterprise and operational environments.
A defining feature of Havex is its ICS-aware reconnaissance. An analyzed payload used classic DCOM-based OPC to enumerate connected control-system resources, including OPC servers and tags, gathering metadata such as server identity, vendor details, versioning, state, bandwidth, and tag characteristics. This capability provided operators with visibility into industrial environments and connected devices. Available analyses did not identify functionality in examined Havex payloads to directly control or modify industrial devices, but testing showed the OPC enumeration component could intermittently crash common OPC platforms and potentially cause denial-of-service conditions for dependent applications.
Havex also supports persistence and anti-forensics. Samples have been observed establishing persistence through Registry Run keys and including a cleanup module to remove traces of infection. Some variants used encoded and encrypted handling of command-and-control data, including Base64 combined with compression or cryptographic transformations. Havex was used as part of broader strategic access operations against energy, utilities, oil and gas, and other critical infrastructure-related organizations, with supply-chain compromise of smaller ICS vendors serving as a path into larger downstream targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Havex RAT gathers information about the infected computers and the networks they are connected to and sends it to servers under the control of the attackers. A program that appears to be have been developed in-house, Havex is also known as Backdoor.Oldrea and the Energetic Bear RAT.
Developed one of only a handful of industrial control system (ICS) specific malware variants through ICS-aware modules for Havex.
Beginning in 2013 and continuing through 2014, the threat actor leveraged Havex malware on Energy Sector networks... Havex is a remote access Trojan (RAT) that communicates with a command and control (C2) server.
Beginning in 2013 and continuing through 2014, the threat actor leveraged Havex malware on Energy Sector networks... Havex is a remote access Trojan (RAT) that communicates with a command and control (C2) server.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
These include phishing emails, redirections to compromised web sites and most recently, trojanized update installers on at least three ICSs vendor web sites, in what are referred to as watering-hole style attacks.
Dragonfly operators hacked websites of at least three different companies providing ICS software... there had already been 250 downloads of the trojanized software... In addition to trojanizing legitimate software used by its victims... the group has more recently begun infecting suppliers
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Among other things, it extracts data from a victim’s Outlook address book and virtual private networking (VPN) programs... It’s capable of collecting passwords
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
ICS‑CERT has identified and analyzed one payload that enumerates all connected network resources, such as computers or shared resources...
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The Havex RAT gathers information about the infected computers and the networks they are connected to
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The Havex RAT gathers information about the infected computers and the networks they are connected to
These data are stored in a file that is created in the user’s TEMP directory under a random name with an extension of '.tmp.dat.' When all information has been written to this file, an encrypted version of this file is created in the same directory with a random name and a '.tmp.yls' extension. The plain text file is then deleted.
The Havex RAT gathers information about the infected computers and the networks they are connected to and sends it to servers under the control of the attackers.
The C&C server can deploy payloads that provide additional functionality.
78 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS-targeting malware cited as demonstrating the ability to disrupt operations, cause outages, and inflict physical damage.
ICS-focused malware/RAT referenced as affecting industrial processes and critical infrastructure environments.
Malware/tooling associated with a Russia-linked ICS-focused threat cluster targeting power/energy environments; described in the context of destructive attacks and custom malware/wiper capability across IT/OT.
Havex is a known espionage backdoor/RAT historically associated with the Berserk Bear/Dragonfly activity set, used to gain remote access and support intrusion operations against critical infrastructure environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.