CHRYSENE
Aliases: OilRig, Greenbug
- First seen
- 2016-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-05-27 08:45:05
- Profile updated
- 2026-07-07 11:50:00
Targeted industries: energy-and-utilities government-and-public-sector
Targeted regions: country_code:sa country_code:ae country_code:qa
Context
Adversaries abusing ICS (based on Dragos Inc adversary list). This threat actor targets organizations involved in oil, gas, and electricity production, primarily in the Gulf region, for espionage purposes. According to one cybersecurity company, the threat actor “compromises a target machine and passes it off to another threat actor for further exploitation.”
Related threat objects
- Cutting Kitten (threat-actor)
- Clever Kitten (threat-actor)
- Charming Kitten (threat-actor)
- Rocket Kitten (threat-actor)
- Greenbug (threat-actor)
- Magic Hound (threat-actor)
- Cleaver (threat-actor)
- Hazel Sandstorm (threat-actor)
Reports & references
- dragos.com — 2017 Review Industrial Control System Threats (report)
- dragos.com — Adversaries (report)
- cfr.org — Chrysene (report)