Karagany

Aliases: Karagny

First seen
2013-01-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Last IoC activity
2026-07-09 02:57:35
Profile updated
2026-07-07 12:44:18

Targeted industries: government-and-public-sector financial-services

Context

Karagany is a remote access trojan (RAT) known for its capabilities to provide backdoor access. It has been associated with cyber espionage campaigns targeting the government and financial sectors. The malware is capable of data exfiltration and executing commands remotely.

Detection coverage

  • 4 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Karaganycore (yara-rule)
  • DITEKSHEN_MALWARE_Win_Karaganyscreenutil (yara-rule)
  • DITEKSHEN_MALWARE_Win_Karaganylistrix (yara-rule)
  • MALPEDIA_Win_Karagany_Auto (yara-rule)

Reports & references

  • paper.seebug.org — Dragonfly Threat Against Western Energy Suppliers (report)
  • Broadcom/Symantec — Dragonfly Energy Sector Cyber Attacks (report)
  • secureworks.com — Iron Liberty (report)
  • Broadcom/Symantec — Dragonfly Western Energy Sector Targeted Sophisticated Attack Group (report)
  • vblocalhost.com — Vb2021 Slowik (report)
  • secureworks.com — Updated Karagany Malware Targets Energy Sector (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Karagany (report)

External references