Trojan.Karagany
MITRE ATT&CK: S0094 View on attack.mitre.org
Aliases: xFrost, Karagany, Trojan.Karagany
- First seen
- 2010-01-01 00:00:00
- Malware type
- rat, trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (1 malicious)
- Last IoC activity
- 2025-11-10 08:21:50
- Profile updated
- 2026-07-07 13:18:09
Targeted industries: energy-and-utilities
Targeted regions: country_code:us country_code:de
Context
Trojan.Karagany is a modular remote access tool used for recon and linked to Dragonfly. The source code for Trojan.Karagany originated from Dream Loader malware which was leaked in 2010 and sold on underground forums.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Trojan.Karagany (S0094). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 1b3cf050d626706d32c1c2c1cbd4975d519cfbdb9bca0f2e66b7e1120030b439 | 2025-11-04 | 1 |
Detection coverage
- 3 YARA rules
- 426 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Application Window Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Software Packing (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Process Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- System Information Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Keylogging (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- Thread Execution Hijacking (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- System Checks (attack-pattern)
- OS Credential Dumping (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Web Protocols (attack-pattern)
- System Owner/User Discovery (attack-pattern)
Used by threat actors
- Dragonfly (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Win_Karaganycore (yara-rule)
- DITEKSHEN_MALWARE_Win_Karaganyscreenutil (yara-rule)
- DITEKSHEN_MALWARE_Win_Karaganylistrix (yara-rule)
Reports & references
- dragos.com — Dymalloy (report)
- Broadcom/Symantec — Viewdocument (report)
- secureworks.com — Updated Karagany Malware Targets Energy Sector (report)
- MITRE ATT&CK — S0094 (report)