U.S. authorities unsealed indictments against three FSB officers and one TsNIIKhM employee over long-running Russian state-sponsored cyber campaigns that penetrated energy-sector organizations and, in one case, deployed TRITON malware against a foreign oil refinery’s safety systems, forcing a shutdown. A joint CISA, FBI, and DOE advisory said the operations spanned 2011 to 2018 and included the Havex malware campaign, remote access to energy networks, theft of enterprise and ICS-related data, and activity consistent with operational preparation against critical infrastructure.
Separate reporting and industry analysis tied related Russian-linked activity to Energetic Bear/Dragonfly/TEMP.Isotope, a cluster associated with intrusions into U.S. state and local government networks and earlier compromises of electric utilities and other critical infrastructure. Officials said some election-support IT systems were accessed in limited cases, but there was no evidence that vote tabulation systems, voting machines, or election data integrity were affected; defenders were urged to strengthen IT/ICS segmentation, apply patches, enforce MFA, restrict remote access, and follow established industrial control system guidance such as NIST SP 800-82.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On 2022-03-24, the UK publicly attributed historic cyber incidents to the FSB's Centre 16, which NCSC said is almost certainly tracked as Energetic Bear, Berserk Bear, and Crouching Yeti. The UK also sanctioned TsNIIKhM for the 2017 Saudi petrochemical plant safety-system incident involving malware capable of causing dangerous physical consequences.
On March 24, 2022, CISA, the FBI, and the DOE jointly published a cybersecurity advisory detailing Russian state-sponsored intrusion campaigns against the energy sector from 2011 to 2018 and recommending mitigations for U.S. defenders.
On March 24, 2022, the U.S. Department of Justice unsealed indictments against three FSB officers and one TsNIIKhM employee for historical hacking campaigns targeting critical infrastructure, including energy sector intrusions and the 2017 TRITON operation.
On November 4, an analysis argued that Energetic Bear was most likely aligned with Russia’s non-military intelligence services, the FSB or SVR, rather than the GRU, and characterized its mission as espionage and operational preparation of the environment.
CyberScoop reported on October 19 that Mandiant had attributed multiple recent intrusions into U.S. state and local networks to TEMP.Isotope, also known as Energetic Bear, based in part on previously associated IP addresses and exploitation of the Microsoft authentication flaw.
On October 9, the FBI and CISA publicized a campaign involving breaches of some election support systems used by state and local officials, while stating the affected systems were not used to tally votes and that there was no evidence election data integrity had been compromised.
On September 18, CISA ordered all federal civilian agencies to update software to address a recently disclosed Microsoft authentication protocol vulnerability later cited in suspected Russian intrusions.
In 2017, Russian actors tied to TsNIIKhM compromised a Middle East-based energy sector organization and used TRITON malware to manipulate a foreign oil refinery’s safety systems, forcing a shutdown for several days.
Beginning in 2016, FSB-linked actors broadly targeted U.S. energy sector networks through a two-stage operation that first compromised third-party vendors, integrators, and suppliers before pivoting into victim enterprise environments.
From 2013 through 2014, the same Russian threat actor leveraged Havex malware on energy sector networks, using spearphishing, compromised websites, and Trojanized ICS vendor software updates to gain access and collect ICS-related information.
A joint CISA/FBI/DOE advisory states that FSB-linked Russian actors began a multi-stage campaign targeting U.S. and international energy sector organizations in 2011, seeking remote access to victim networks and later exfiltrating enterprise and ICS-related data.
After the TRITON incident, Schneider Electric issued a patch to mitigate the attack vector used against Triconex safety systems. The source does not explicitly anchor the patch to a specific date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcegov.uk
Open sourceus-cert.cisa.gov
Open sourcepylos.co
Open sourcecyberscoop.com
Open sourcecrowdstrike.com
Open sourcecsrc.nist.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.