ALLANITE

MITRE ATT&CK: G1000 View on attack.mitre.org

Aliases: Palmetto Fusion, Allanite, ALLANITE

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-08-31 08:19:27

Targeted industries: energy-and-utilities

Targeted regions: country_code:us country_code:gb

Context

ALLANITE is a suspected Russian cyber espionage group, that has primarily targeted the electric utility sector within the United States and United Kingdom. The group's tactics and techniques are reportedly similar to Dragonfly, although ALLANITEs technical capabilities have not exhibited disruptive or destructive abilities. It has been suggested that the group maintains a presence in ICS for the purpose of gaining understanding of processes and to maintain persistence.

Malware & tools used

  • Valid Accounts (attack-pattern)
  • Screen Capture (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Drive-by Compromise (attack-pattern)

Reports & references

  • dragos.com — Adversaries (report)
  • dragos.com — 20180510Allanite (report)
  • MITRE ATT&CK — G1000 (report)
  • dragos.com — Allanite (report)

External references