LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0035: Dragonfly

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.[1][2] Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.[3][4][5][6][7][8][9]

EnterpriseG0035GroupObject v4.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Dragonfly matters because ATT&CK describes it as a long-running cyber espionage group attributed to Russia’s FSB Center 16, with reporting tied to defense, aviation, government, industrial control systems, and critical infrastructure targets. For leaders, the decision value is not the name alone; it is whether the organization can withstand supply chain, spearphishing, drive-by compromise, credential theft, discovery, and lateral movement behaviors that ATT&CK associates with this group.

Executive priority

Prioritize Dragonfly as a resilience and assurance scenario for organizations with critical infrastructure, ICS, defense, aviation, government, or supplier exposure. Executives should ask whether identity controls, Windows credential protections, remote access governance, supplier risk processes, and SOC visibility can produce evidence during an incident. Because Dragonfly 2.0 has been revoked into this object across enterprise and ICS contexts, teams should avoid treating older reporting as unrelated without analyst review.

Technical view

ATT&CK provides no official detection text for this group, so coverage should be validated through the linked behaviors and software. The relationship set emphasizes Windows credential access and administration tooling, including Mimikatz, PsExec, Net, Reg, netsh, Impacket, CrackMapExec, Backdoor.Oldrea, Trojan.Karagany, and MCMD. SOC and IR teams should map detections to credential dumping from SAM, NTDS, and LSA Secrets; registry querying; network and remote system discovery; user discovery; RDP lateral movement; local data collection; and ICS-related drive-by and supply chain compromise scenarios.

Likely telemetry

  • Windows security events and authentication logs, especially domain controller and privileged account activity
  • Endpoint process creation and command-line telemetry for Net, Reg, netsh, PsExec-like execution, credential dumping tools, and remote access tooling
  • Registry access telemetry, especially sensitive hives and security-related paths
  • Active Directory and domain controller monitoring for NTDS access, replication-like activity, and unusual administrative access
  • RDP session logs and remote logon records

Detection direction

  • Build behavior-based coverage rather than relying only on group or alias names, because Dragonfly has many aliases and Dragonfly 2.0 is revoked into this object.
  • Validate detections for Windows credential access paths: SAM, NTDS.dit, LSA Secrets, Mimikatz-like behavior, and suspicious access from hosts or accounts that do not normally administer identity systems.
  • Tune administrative-tool detections for context: Net, Reg, netsh, PsExec, Impacket, and CrackMapExec may be legitimate in IT operations, so baselines for administrators, jump hosts, maintenance windows, and domain controllers are essential.
  • Correlate discovery commands, registry queries, RDP use, and credential access into incident narratives; single events may be noisy, but sequences can indicate hands-on-keyboard activity.
  • For ICS or critical infrastructure environments, validate visibility at IT/OT boundaries and supplier pathways because the ATT&CK relationships include ICS drive-by compromise and supply chain compromise.

Mitigation priorities

  • Start with identity hardening: reduce standing privilege, protect domain controllers, monitor privileged accounts, and restrict credential exposure on Windows systems.
  • Govern remote administration and lateral movement paths, including RDP and tools such as PsExec; require approved jump paths and strong authentication where applicable.
  • Improve endpoint and domain controller logging before assuming detection coverage, especially for process execution, registry access, and credential store access.
  • Strengthen supplier and software update assurance for environments where ICS or critical infrastructure dependency exists.
  • Segment and monitor IT/OT boundaries and limit unnecessary access from enterprise systems into control system environments.
Additional notes and limits

The supplied ATT&CK object identifies Dragonfly as a group with multiple aliases and links it to enterprise and ICS-relevant behaviors. The most actionable relationship context is the use of Windows tools, credential dumping techniques, remote access/lateral movement, discovery, and ICS supply chain or drive-by compromise techniques. Local asset criticality, supplier relationships, identity architecture, and logging maturity determine how material this is for a specific organization.

ATT&CK does not provide official detection guidance, object-level platforms, or object-level tactics for this group in the supplied fields. The relationship list is not necessarily complete, and several related descriptions are truncated. This take does not assert current activity, customer exposure, or guaranteed detection coverage; environment-specific validation is required.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Dragonfly

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.[1][2] Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.[3][4][5][6][7][8][9]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

56 rows
DomainIDNameRelationship / procedure
EnterpriseT1560Archive Collected Data

Dragonfly has compressed data into .zip files prior to exfiltration.[10]

EnterpriseT1113Screen Capture

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).[10][5][7]

EnterpriseT1564.002Hidden UsersSub-technique

Dragonfly has modified the Registry to hide created user accounts.[10]

EnterpriseT1505.003Web ShellSub-technique

Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.[10]

EnterpriseT1204.002Malicious FileSub-technique

Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.[7]

EnterpriseT1591.002Business RelationshipsSub-technique

Dragonfly has collected open source information to identify relationships between organizations for targeting purposes.[7]

EnterpriseT1078Valid Accounts

Dragonfly has compromised user credentials and used valid accounts for operations.[10][7][8]

EnterpriseT1016System Network Configuration Discovery

Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain.[10]

EnterpriseT1584.004ServerSub-technique

Dragonfly has compromised legitimate websites to host C2 and malware modules.[7]

EnterpriseT1083File and Directory Discovery

Dragonfly has used a batch script to gather folder and file names from victim hosts.[10][7][8]

EnterpriseT1136.001Local AccountSub-technique

Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target.[10]

EnterpriseT1221Template Injection

Dragonfly has injected SMB URLs into malicious Word spearphishing attachments to initiate Forced Authentication.[10]

EnterpriseT1203Exploitation for Client Execution

Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system.[7]

EnterpriseT1110.002Password CrackingSub-technique

Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec.[10][12]

EnterpriseT1608.004Drive-by TargetSub-technique

Dragonfly has compromised websites to redirect traffic and to host exploit kits.[7]

EnterpriseT1012Query Registry

Dragonfly has queried the Registry to identify victim information.[10]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Dragonfly has sent emails with malicious attachments to gain initial access.[7]

EnterpriseT1189Drive-by Compromise

Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit.[4][10][7]

EnterpriseT1583.001DomainsSub-technique

Dragonfly has registered domains for targeting intended victims.[8]

EnterpriseT1003.002Security Account ManagerSub-technique

Dragonfly has dropped and executed SecretsDump to dump password hashes.[10]

EnterpriseT1598.002Spearphishing AttachmentSub-technique

Dragonfly has used spearphishing with Microsoft Office attachments to enable harvesting of user credentials.[10]

EnterpriseT1005Data from Local System

Dragonfly has collected data from local victim systems.[10]

EnterpriseT1070.004File DeletionSub-technique

Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots.[10]

EnterpriseT1059Command and Scripting Interpreter

Dragonfly has used the command line for execution.[10]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys.[10]

EnterpriseT1686Disable or Modify System Firewall

Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389.[10]

EnterpriseT1112Modify Registry

Dragonfly has modified the Registry to perform multiple techniques through the use of Reg.[10]

EnterpriseT1588.002ToolSub-technique

Dragonfly has obtained and used tools such as Mimikatz, CrackMapExec, and PsExec.[4]

EnterpriseT1195.002Compromise Software Supply ChainSub-technique

Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores.[4][7]

EnterpriseT1036.010Masquerade Account NameSub-technique

Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account.[10]

EnterpriseT1003.003NTDSSub-technique

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.[10][13]

EnterpriseT1098.007Additional Local or Domain GroupsSub-technique

Dragonfly has added newly created accounts to the administrators group to maintain elevated access.[10]

EnterpriseT1583.003Virtual Private ServerSub-technique

Dragonfly has acquired VPS infrastructure for use in malicious campaigns.[7]

EnterpriseT1059.003Windows Command ShellSub-technique

Dragonfly has used various types of scripting to perform operations, including batch scripts.[10]

EnterpriseT1071.002File Transfer ProtocolsSub-technique

Dragonfly has used SMB for C2.[10]

EnterpriseT1598.003Spearphishing LinkSub-technique

Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites.[10]

EnterpriseT1053.005Scheduled TaskSub-technique

Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files.[10]

EnterpriseT1069.002Domain GroupsSub-technique

Dragonfly has used batch scripts to enumerate administrators and users in the domain.[10]

EnterpriseT1114.002Remote Email CollectionSub-technique

Dragonfly has accessed email accounts using Outlook Web Access.[10]

EnterpriseT1595.002Vulnerability ScanningSub-technique

Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services.[8]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence.[10]

EnterpriseT1105Ingress Tool Transfer

Dragonfly has copied and installed tools for operations once in the victim environment.[10]

EnterpriseT1133External Remote Services

Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks.[10][8]

EnterpriseT1003.004LSA SecretsSub-technique

Dragonfly has dropped and executed SecretsDump to dump password hashes.[10][13]

EnterpriseT1190Exploit Public-Facing Application

Dragonfly has conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.[8]

EnterpriseT1135Network Share Discovery

Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems.[10]

EnterpriseT1110Brute Force

Dragonfly has attempted to brute force credentials to gain access.[8]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Dragonfly has moved laterally via RDP.[10]

EnterpriseT1187Forced Authentication

Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems.[10][7]

EnterpriseT1033System Owner/User Discovery

Dragonfly used the command query user on victim hosts.[10]

EnterpriseT1074.001Local Data StagingSub-technique

Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it.[10]

EnterpriseT1059.001PowerShellSub-technique

Dragonfly has used PowerShell scripts for execution.[10][5]

EnterpriseT1210Exploitation of Remote Services

Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers.[8]

EnterpriseT1059.006PythonSub-technique

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.[10]

EnterpriseT1018Remote System Discovery

Dragonfly has likely obtained a list of hosts in the victim environment.[10]

EnterpriseT1087.002Domain AccountSub-technique

Dragonfly has used batch scripts to enumerate users on a victim domain controller.[10]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0074: Dragonfly 2.0

Dragonfly 2.0 is a suspected Russian group that has targeted government entities and multiple U.S. critical infrastructure sectors since at least December 2015. [1] [2] There is debate over the extent of overlap between Dragonfly 2.0 and Dragonfly, but there is sufficient evidence to lead to these being tracked as two separate groups. [3][4]

Revoked/deprecated
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
ToolEnterprise

S0488: CrackMapExec

CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.[1]

Windows
ToolEnterprise

S0075: Reg

Reg is a Windows utility used to interact with the Windows Registry. It can be used at the command-line interface to query, add, modify, and remove information. [1]

Utilities such as Reg are known to be used by persistent threats. [2]

Windows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0108: netsh

netsh is a scripting utility used to interact with networking components on local or remote systems. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
4.0
Created
Modified
Raw hash
af4de2ac45e01410...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.14.0Current bundleaf4de2ac45e0…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    DOJ Russia Targeting Critical Infrastructure March 2022

    Department of Justice. (2022, March 24). Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide. Retrieved April 5, 2022.

    Open source URL
  2. [2]
    UK GOV FSB Factsheet April 2022

    UK Gov. (2022, April 5). Russia's FSB malign activity: factsheet. Retrieved April 5, 2022.

    Open source URL
  3. [3]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  4. [4]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  5. [5]
    Symantec Dragonfly Sept 2017

    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

    Open source URL
  6. [6]
    Fortune Dragonfly 2.0 Sept 2017

    Hackett, R. (2017, September 6). Hackers Have Penetrated Energy Grid, Symantec Warns. Retrieved June 6, 2018.

  7. [7]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  8. [8]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  9. [9]
    Symantec Dragonfly 2.0 October 2017

    Symantec. (2017, October 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved April 19, 2022.

    Open source URL
  10. [10]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  11. [11]
    Secureworks MCMD July 2019

    Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.

    Open source URL
  12. [12]
    Kali Hydra

    Kali. (2014, February 18). THC-Hydra. Retrieved November 2, 2017.

    Open source URL
  13. [13]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  14. [14]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  15. [15]
    BROMINE

    (Citation: Microsoft Threat Actor Naming July 2023)

  16. [16]
    BROMINE

    (Citation: Microsoft Threat Actor Naming July 2023)

  17. [17]
    BROMINE

    (Citation: Microsoft Threat Actor Naming July 2023)

  18. [18]
    Berserk Bear

    (Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  19. [19]
    Berserk Bear

    (Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  20. [20]
    Berserk Bear

    (Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  21. [21]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  22. [22]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  23. [23]
    Crouching Yeti

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  24. [24]
    Crouching Yeti

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  25. [25]
    Crouching Yeti

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  26. [26]
    DOJ Russia Targeting Critical Infrastructure March 2022

    Department of Justice. (2022, March 24). Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide. Retrieved April 5, 2022.

    Open source URL
  27. [27]
    DOJ Russia Targeting Critical Infrastructure March 2022

    Department of Justice. (2022, March 24). Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide. Retrieved April 5, 2022.

    Open source URL
  28. [28]
    DYMALLOY

    (Citation: Dragos DYMALLOY )(Citation: UK GOV FSB Factsheet April 2022)

  29. [29]
    DYMALLOY

    (Citation: Dragos DYMALLOY )(Citation: UK GOV FSB Factsheet April 2022)

  30. [30]
    DYMALLOY

    (Citation: Dragos DYMALLOY )(Citation: UK GOV FSB Factsheet April 2022)

  31. [31]
    Dragonfly

    (Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  32. [32]
    Dragonfly

    (Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  33. [33]
    Dragonfly

    (Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  34. [34]
    Dragos DYMALLOY

    Dragos. (n.d.). DYMALLOY. Retrieved August 20, 2020.

    Open source URL
  35. [35]
    Dragos DYMALLOY

    Dragos. (n.d.). DYMALLOY. Retrieved August 20, 2020.

    Open source URL
  36. [36]
    Dragos DYMALLOY

    Dragos. (n.d.). DYMALLOY. Retrieved August 20, 2020.

    Open source URL
  37. [37]
    Energetic Bear

    (Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Secureworks MCMD July 2019)(Citation: Secureworks Karagany July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  38. [38]
    Energetic Bear

    (Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Secureworks MCMD July 2019)(Citation: Secureworks Karagany July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  39. [39]
    Energetic Bear

    (Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Secureworks MCMD July 2019)(Citation: Secureworks Karagany July 2019)(Citation: Gigamon Berserk Bear October 2021)(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022)

  40. [40]
    Fortune Dragonfly 2.0 Sept 2017

    Hackett, R. (2017, September 6). Hackers Have Penetrated Energy Grid, Symantec Warns. Retrieved June 6, 2018.

  41. [41]
    Fortune Dragonfly 2.0 Sept 2017

    Hackett, R. (2017, September 6). Hackers Have Penetrated Energy Grid, Symantec Warns. Retrieved June 6, 2018.

  42. [42]
    Ghost Blizzard

    (Citation: Microsoft Threat Actor Naming July 2023)

  43. [43]
    Ghost Blizzard

    (Citation: Microsoft Threat Actor Naming July 2023)

  44. [44]
    Ghost Blizzard

    (Citation: Microsoft Threat Actor Naming July 2023)

  45. [45]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  46. [46]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  47. [47]
    IRON LIBERTY

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: Secureworks MCMD July 2019)(Citation: Secureworks Karagany July 2019)(Citation: UK GOV FSB Factsheet April 2022)

  48. [48]
    IRON LIBERTY

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: Secureworks MCMD July 2019)(Citation: Secureworks Karagany July 2019)(Citation: UK GOV FSB Factsheet April 2022)

  49. [49]
    IRON LIBERTY

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: Secureworks MCMD July 2019)(Citation: Secureworks Karagany July 2019)(Citation: UK GOV FSB Factsheet April 2022)

  50. [50]
    Mandiant Ukraine Cyber Threats January 2022

    Hultquist, J. (2022, January 20). Anticipating Cyber Threats as the Ukraine Crisis Escalates. Retrieved January 24, 2022.

    Open source URL
  51. [51]
    Mandiant Ukraine Cyber Threats January 2022

    Hultquist, J. (2022, January 20). Anticipating Cyber Threats as the Ukraine Crisis Escalates. Retrieved January 24, 2022.

    Open source URL
  52. [52]
    Mandiant Ukraine Cyber Threats January 2022

    Hultquist, J. (2022, January 20). Anticipating Cyber Threats as the Ukraine Crisis Escalates. Retrieved January 24, 2022.

    Open source URL
  53. [53]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  54. [54]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  55. [55]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  56. [56]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  57. [57]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  58. [58]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  59. [59]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  60. [60]
    Secureworks MCMD July 2019

    Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.

    Open source URL
  61. [61]
    Secureworks MCMD July 2019

    Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.

    Open source URL
  62. [62]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  63. [63]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  64. [64]
    Symantec Dragonfly 2.0 October 2017

    Symantec. (2017, October 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved April 19, 2022.

    Open source URL
  65. [65]
    Symantec Dragonfly 2.0 October 2017

    Symantec. (2017, October 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved April 19, 2022.

    Open source URL
  66. [66]
    Symantec Dragonfly Sept 2017

    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

    Open source URL
  67. [67]
    Symantec Dragonfly Sept 2017

    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

    Open source URL
  68. [68]
    TEMP.Isotope

    (Citation: Mandiant Ukraine Cyber Threats January 2022)(Citation: Gigamon Berserk Bear October 2021)

  69. [69]
    TEMP.Isotope

    (Citation: Mandiant Ukraine Cyber Threats January 2022)(Citation: Gigamon Berserk Bear October 2021)

  70. [70]
    TEMP.Isotope

    (Citation: Mandiant Ukraine Cyber Threats January 2022)(Citation: Gigamon Berserk Bear October 2021)

  71. [71]
    TG-4192

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: UK GOV FSB Factsheet April 2022)

  72. [72]
    TG-4192

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: UK GOV FSB Factsheet April 2022)

  73. [73]
    TG-4192

    (Citation: Secureworks IRON LIBERTY July 2019)(Citation: UK GOV FSB Factsheet April 2022)

  74. [74]
    UK GOV FSB Factsheet April 2022

    UK Gov. (2022, April 5). Russia's FSB malign activity: factsheet. Retrieved April 5, 2022.

    Open source URL
  75. [75]
    UK GOV FSB Factsheet April 2022

    UK Gov. (2022, April 5). Russia's FSB malign activity: factsheet. Retrieved April 5, 2022.

    Open source URL
  76. [76]
    mitre-attackG0035
    Open source URL
  77. [77]
    mitre-attackG0035
    Open source URL
  78. [78]
    mitre-attackG0035
    Open source URL
  79. [79]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  80. [80]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  81. [81]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  82. [82]
    Symantec Dragonfly Sept 2017

    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

    Open source URL
  83. [83]
    Symantec Dragonfly Sept 2017

    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

    Open source URL
  84. [84]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  85. [85]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  86. [86]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  87. [87]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  88. [88]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  89. [89]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  90. [90]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  91. [91]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  92. [92]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  93. [93]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  94. [94]
    Secureworks MCMD July 2019

    Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.

    Open source URL
  95. [95]
    Secureworks MCMD July 2019

    Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.

    Open source URL
  96. [96]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  97. [97]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  98. [98]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  99. [99]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  100. [100]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  101. [101]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  102. [102]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  103. [103]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  104. [104]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  105. [105]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  106. [106]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  107. [107]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  108. [108]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  109. [109]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  110. [110]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  111. [111]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  112. [112]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  113. [113]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  114. [114]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  115. [115]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  116. [116]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  117. [117]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  118. [118]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  119. [119]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  120. [120]
    Kali Hydra

    Kali. (2014, February 18). THC-Hydra. Retrieved November 2, 2017.

    Open source URL
  121. [121]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  122. [122]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  123. [123]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  124. [124]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  125. [125]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  126. [126]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  127. [127]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  128. [128]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  129. [129]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  130. [130]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  131. [131]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  132. [132]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  133. [133]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  134. [134]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  135. [135]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  136. [136]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  137. [137]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  138. [138]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  139. [139]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  140. [140]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  141. [141]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  142. [142]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  143. [143]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  144. [144]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  145. [145]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  146. [146]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  147. [147]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  148. [148]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  149. [149]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  150. [150]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  151. [151]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  152. [152]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  153. [153]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  154. [154]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  155. [155]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  156. [156]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  157. [157]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  158. [158]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  159. [159]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  160. [160]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  161. [161]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  162. [162]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  163. [163]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  164. [164]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  165. [165]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  166. [166]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  167. [167]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  168. [168]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  169. [169]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  170. [170]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  171. [171]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  172. [172]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  173. [173]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  174. [174]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  175. [175]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  176. [176]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  177. [177]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  178. [178]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  179. [179]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  180. [180]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  181. [181]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  182. [182]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  183. [183]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  184. [184]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  185. [185]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  186. [186]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  187. [187]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  188. [188]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  189. [189]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  190. [190]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  191. [191]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  192. [192]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  193. [193]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  194. [194]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  195. [195]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  196. [196]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  197. [197]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  198. [198]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  199. [199]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  200. [200]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  201. [201]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  202. [202]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  203. [203]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  204. [204]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  205. [205]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  206. [206]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  207. [207]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  208. [208]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  209. [209]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  210. [210]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  211. [211]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  212. [212]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  213. [213]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  214. [214]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  215. [215]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  216. [216]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  217. [217]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  218. [218]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  219. [219]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  220. [220]
    Symantec Dragonfly Sept 2017

    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

    Open source URL
  221. [221]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  222. [222]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  223. [223]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  224. [224]
    Symantec Dragonfly Sept 2017

    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

    Open source URL
  225. [225]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  226. [226]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  227. [227]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  228. [228]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  229. [229]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  230. [230]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  231. [231]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  232. [232]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  233. [233]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.