Dragonfly
MITRE ATT&CK: G0035 View on attack.mitre.org
Aliases: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE, BERSERK BEAR, ALLANITE, CASTLE, Dragonfly, Group 24, Havex, Koala Team, ATK6, ITG15, Blue Kraken
- First seen
- 2010-01-01 00:00:00
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-06-16 14:45:04
- Profile updated
- 2026-07-07 12:32:45
Targeted industries: defense-and-aerospace government-and-public-sector energy-and-utilities technology-and-telecommunications transportation-and-logistics
Context
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.
Detection coverage
- 13 YARA rules
- 987 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Hidden Users (attack-pattern)
- Web Shell (attack-pattern)
- Malicious File (attack-pattern)
- Business Relationships (attack-pattern)
- Valid Accounts (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Server (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Local Account (attack-pattern)
- Template Injection (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Password Cracking (attack-pattern)
- Drive-by Target (attack-pattern)
- Query Registry (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Domains (attack-pattern)
- Security Account Manager (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Data from Local System (attack-pattern)
- File Deletion (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
Related threat objects
- Dragonfly 2.0 (threat-actor)
Reports & references
- dragos.com — 2017 Review Industrial Control System Threats (report)
- dragos.com — Adversaries (report)
- web.archive.org — 330401 (report)
- gov.uk — Russias Fsb Malign Activity Factsheet (report)
- paper.seebug.org — Dragonfly Threat Against Western Energy Suppliers (report)
- netresec.com (report)
- threatpost.com — 104772 (report)
- cfr.org — Crouching Yeti (report)
- reuters.com — Us Ukraine Cyber Attack Energy Iduskbn1521Ba (report)
- dragos.com — Crashoverride 01 (report)
- independent.ie — Statesponsored Hackers Targeted Eirgrid Electricity Network In Devious Attack 36005921 (report)
- riskiq.com — Energetic Bear (report)
- Broadcom/Symantec — Dragonfly Energy Sector Cyber Attacks (report)
- kaspersky.com — Crouching Yeti Energetic Bear Malware Threat (report)
- sans.org — Impact Dragonfly Malware Industrial Control Systems 36672 (report)
- MITRE ATT&CK — G0035 (report)
- secureworks.com — Resurgent Iron Liberty Targeting Energy Sector (report)
- cfr.org — Dymalloy (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- fortune.com — Hack Energy Grid Symantec (report)
- dragos.com — Dymalloy (report)
- secureworks.com — Mcmd Malware Analysis (report)
- Broadcom/Symantec — Viewdocument (report)
- Broadcom/Symantec — Dragonfly Threat Against Western Energy Suppliers (report)
External references
- mitre-attack — G0035
- DYMALLOY
- Berserk Bear
- TEMP.Isotope
- Ghost Blizzard
- BROMINE
- Crouching Yeti
- IRON LIBERTY
- TG-4192
- Dragonfly
- Energetic Bear
- CISA AA20-296A Berserk Bear December 2020
- DOJ Russia Targeting Critical Infrastructure March 2022
- Dragos DYMALLOY
- Fortune Dragonfly 2.0 Sept 2017
- Mandiant Ukraine Cyber Threats January 2022
- Microsoft Threat Actor Naming July 2023
- Secureworks MCMD July 2019
- Secureworks IRON LIBERTY July 2019
- Secureworks Karagany July 2019