Havex, also known as Backdoor.Oldrea and the Energetic Bear RAT, is a Windows remote access trojan used by Dragonfly, also known as Energetic Bear, in espionage campaigns against energy-sector organizations and industrial control system (ICS) environments. U.S. authorities have linked the Dragonfly/Havex campaign to Russia’s Federal Security Service Center 16. Targets included oil and gas companies, electric utilities, nuclear power facilities, power transmission companies, and ICS software suppliers.
Havex communicates with attacker-controlled command-and-control servers and supports additional payloads that extend its functionality. It collects host and network information, including usernames, running processes, and network adapter configuration, and exfiltrates information from Outlook address books and VPN applications. Some samples incorporate a publicly available browser password recovery tool. It establishes persistence through registry-based autostart entries, injects itself into the Windows shell process, and includes a cleanup module that removes traces of infection. Variants use combinations of Base64 encoding, compression, XOR transformations, and RSA encryption to process command-and-control data.
Its ICS-focused reconnaissance payload enumerates network computers and shared resources and uses classic DCOM-based OPC to discover control-system resources. It collects OPC server properties and enumerates tags and their attributes, enabling attackers to map industrial environments. Analyzed payloads did not contain functionality to control or modify connected industrial devices, although testing demonstrated intermittent crashes of common OPC platforms that could disrupt dependent applications.
Distribution has included phishing and spearphishing emails, malicious spam, watering-hole attacks, and software supply-chain compromises. Attackers compromised ICS vendor websites and embedded Havex in legitimate software installers and updates, allowing infection when customers installed the altered packages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Havex RAT gathers information about the infected computers and the networks they are connected to and sends it to servers under the control of the attackers. A program that appears to be have been developed in-house, Havex is also known as Backdoor.Oldrea and the Energetic Bear RAT.
Developed one of only a handful of industrial control system (ICS) specific malware variants through ICS-aware modules for Havex.
Beginning in 2013 and continuing through 2014, the threat actor leveraged Havex malware on Energy Sector networks... Havex is a remote access Trojan (RAT) that communicates with a command and control (C2) server.
Beginning in 2013 and continuing through 2014, the threat actor leveraged Havex malware on Energy Sector networks... Havex is a remote access Trojan (RAT) that communicates with a command and control (C2) server.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
These include phishing emails, redirections to compromised web sites and most recently, trojanized update installers on at least three ICSs vendor web sites, in what are referred to as watering-hole style attacks.
Dragonfly operators hacked websites of at least three different companies providing ICS software... there had already been 250 downloads of the trojanized software... In addition to trojanizing legitimate software used by its victims... the group has more recently begun infecting suppliers
ICS‑CERT has identified and analyzed one payload that enumerates all connected network resources, such as computers or shared resources...
The Havex RAT gathers information about the infected computers and the networks they are connected to
The Havex RAT gathers information about the infected computers and the networks they are connected to
These data are stored in a file that is created in the user’s TEMP directory under a random name with an extension of '.tmp.dat.' When all information has been written to this file, an encrypted version of this file is created in the same directory with a random name and a '.tmp.yls' extension. The plain text file is then deleted.
The Havex RAT gathers information about the infected computers and the networks they are connected to and sends it to servers under the control of the attackers.
80 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS-targeting malware cited as demonstrating the ability to disrupt operations, cause outages, and inflict physical damage.
ICS-focused malware/RAT referenced as affecting industrial processes and critical infrastructure environments.
Malware/tooling associated with a Russia-linked ICS-focused threat cluster targeting power/energy environments; described in the context of destructive attacks and custom malware/wiper capability across IT/OT.
Havex is a known espionage backdoor/RAT historically associated with the Berserk Bear/Dragonfly activity set, used to gain remote access and support intrusion operations against critical infrastructure environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.