Karagany
Aliases: Karagny
- First seen
- 2013-01-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Last IoC activity
- 2026-07-09 02:57:35
- Profile updated
- 2026-07-07 12:44:18
Targeted industries: government-and-public-sector financial-services
Context
Karagany is a remote access trojan (RAT) known for its capabilities to provide backdoor access. It has been associated with cyber espionage campaigns targeting the government and financial sectors. The malware is capable of data exfiltration and executing commands remotely.
Detection coverage
- 4 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Karaganycore (yara-rule)
- DITEKSHEN_MALWARE_Win_Karaganyscreenutil (yara-rule)
- DITEKSHEN_MALWARE_Win_Karaganylistrix (yara-rule)
- MALPEDIA_Win_Karagany_Auto (yara-rule)
Reports & references
- paper.seebug.org — Dragonfly Threat Against Western Energy Suppliers (report)
- Broadcom/Symantec — Dragonfly Energy Sector Cyber Attacks (report)
- secureworks.com — Iron Liberty (report)
- Broadcom/Symantec — Dragonfly Western Energy Sector Targeted Sophisticated Attack Group (report)
- vblocalhost.com — Vb2021 Slowik (report)
- secureworks.com — Updated Karagany Malware Targets Energy Sector (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Karagany (report)