Dragonfly

MITRE ATT&CK: G0035 View on attack.mitre.org

Aliases: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE, BERSERK BEAR, ALLANITE, CASTLE, Dragonfly, Group 24, Havex, Koala Team, ATK6, ITG15, Blue Kraken

First seen
2010-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Last IoC activity
2026-06-16 14:45:04
Profile updated
2026-07-07 12:32:45

Targeted industries: defense-and-aerospace government-and-public-sector energy-and-utilities technology-and-telecommunications transportation-and-logistics

Context

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.

Detection coverage

  • 13 YARA rules
  • 987 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Hidden Users (attack-pattern)
  • Web Shell (attack-pattern)
  • Malicious File (attack-pattern)
  • Business Relationships (attack-pattern)
  • Valid Accounts (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Server (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Local Account (attack-pattern)
  • Template Injection (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Password Cracking (attack-pattern)
  • Drive-by Target (attack-pattern)
  • Query Registry (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Domains (attack-pattern)
  • Security Account Manager (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Data from Local System (attack-pattern)
  • File Deletion (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)

Related threat objects

Reports & references

  • dragos.com — 2017 Review Industrial Control System Threats (report)
  • dragos.com — Adversaries (report)
  • web.archive.org — 330401 (report)
  • gov.uk — Russias Fsb Malign Activity Factsheet (report)
  • paper.seebug.org — Dragonfly Threat Against Western Energy Suppliers (report)
  • netresec.com (report)
  • threatpost.com — 104772 (report)
  • cfr.org — Crouching Yeti (report)
  • reuters.com — Us Ukraine Cyber Attack Energy Iduskbn1521Ba (report)
  • dragos.com — Crashoverride 01 (report)
  • independent.ie — Statesponsored Hackers Targeted Eirgrid Electricity Network In Devious Attack 36005921 (report)
  • riskiq.com — Energetic Bear (report)
  • Broadcom/Symantec — Dragonfly Energy Sector Cyber Attacks (report)
  • kaspersky.com — Crouching Yeti Energetic Bear Malware Threat (report)
  • sans.org — Impact Dragonfly Malware Industrial Control Systems 36672 (report)
  • MITRE ATT&CK — G0035 (report)
  • secureworks.com — Resurgent Iron Liberty Targeting Energy Sector (report)
  • cfr.org — Dymalloy (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • fortune.com — Hack Energy Grid Symantec (report)
  • dragos.com — Dymalloy (report)
  • secureworks.com — Mcmd Malware Analysis (report)
  • Broadcom/Symantec — Viewdocument (report)
  • Broadcom/Symantec — Dragonfly Threat Against Western Energy Suppliers (report)

External references