Dragonfly
Also reported as TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti and 4 other names.
Reports per quarter
Techniques seen in the last two years
- T1133 3 reports in ATT&CK
- T1016 2 reports in ATT&CK
- T1018 2 reports in ATT&CK
- T1033 2 reports in ATT&CK
- T1046 2 reports reports only
- T1049 2 reports reports only
- T1053 2 reports reports only
- T1053.005 2 reports in ATT&CK
- T1057 2 reports reports only
- T1070.004 2 reports in ATT&CK
Show all 90 techniques Show fewer
- T1078.003 2 reports reports only
- T1083 2 reports in ATT&CK
- T1090 2 reports reports only
- T1105 2 reports in ATT&CK
- T1110 2 reports in ATT&CK
- T1134 2 reports reports only
- T1135 2 reports in ATT&CK
- T1189 2 reports in ATT&CK
- T1190 2 reports in ATT&CK
- T1219.002 2 reports reports only
- T1222 2 reports reports only
- T1484.001 2 reports reports only
- T1485 2 reports reports only
- T1490 2 reports reports only
- T1529 2 reports reports only
- T1558 2 reports reports only
- T1567 2 reports reports only
- T1567.004 2 reports reports only
- T1569.002 2 reports reports only
- T1602.002 2 reports reports only
- T1665 2 reports reports only
- T1680 2 reports reports only
- T0807 1 report reports only
- T0809 1 report reports only
- T0816 1 report reports only
- T0822 1 report reports only
- T0823 1 report reports only
- T0827 1 report reports only
- T0829 1 report reports only
- T0840 1 report reports only
- T0846 1 report reports only
- T0852 1 report reports only
- T0859 1 report reports only
- T0886 1 report reports only
- T0888 1 report reports only
- T0892 1 report reports only
- T1003 1 report reports only
- T1003.002 1 report in ATT&CK
- T1003.003 1 report in ATT&CK
- T1003.004 1 report in ATT&CK
- T1005 1 report in ATT&CK
- T1012 1 report in ATT&CK
- T1021 1 report reports only
- T1036.010 1 report in ATT&CK
- T1059 1 report in ATT&CK
- T1059.001 1 report in ATT&CK
- T1059.003 1 report in ATT&CK
- T1059.006 1 report in ATT&CK
- T1069.002 1 report in ATT&CK
- T1071.002 1 report in ATT&CK
- T1074.001 1 report in ATT&CK
- T1078 1 report in ATT&CK
- T1087 1 report reports only
- T1087.002 1 report in ATT&CK
- T1098.007 1 report in ATT&CK
- T1110.002 1 report in ATT&CK
- T1112 1 report in ATT&CK
- T1113 1 report in ATT&CK
- T1114.002 1 report in ATT&CK
- T1136.001 1 report in ATT&CK
- T1187 1 report in ATT&CK
- T1195.002 1 report in ATT&CK
- T1203 1 report in ATT&CK
- T1204.002 1 report in ATT&CK
- T1221 1 report in ATT&CK
- T1505.003 1 report in ATT&CK
- T1547.001 1 report in ATT&CK
- T1560 1 report in ATT&CK
- T1561.002 1 report reports only
- T1564.002 1 report in ATT&CK
- T1566.001 1 report in ATT&CK
- T1583.001 1 report in ATT&CK
- T1583.003 1 report in ATT&CK
- T1584.004 1 report in ATT&CK
- T1588.002 1 report in ATT&CK
- T1591.002 1 report in ATT&CK
- T1595.002 1 report in ATT&CK
- T1598.002 1 report in ATT&CK
- T1598.003 1 report in ATT&CK
- T1608.004 1 report in ATT&CK
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2010-0232 KEV
- CVE-2010-1256
- CVE-2010-1899
- CVE-2010-2730
- CVE-2010-2883 KEV
- CVE-2010-3972
- CVE-2010-4398 KEV
- CVE-2011-0611 KEV
- CVE-2011-3402 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-1723 KEV ransomware
Show all 101 CVEs Show fewer
- CVE-2012-1889 KEV
- CVE-2012-2531
- CVE-2012-2532
- CVE-2012-3174
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5076 KEV
- CVE-2012-5687
- CVE-2013-0422 KEV ransomware
- CVE-2013-0431 KEV ransomware
- CVE-2013-1347 KEV
- CVE-2013-1488
- CVE-2013-1690 KEV
- CVE-2013-2423 KEV
- CVE-2013-2465 KEV ransomware
- CVE-2013-5947
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-2360 KEV
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0262 KEV
- CVE-2017-11292 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-15906
- CVE-2017-8759 KEV
- CVE-2017-9841 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-1579
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2019-0211 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-17026 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-11901
- CVE-2020-1472 KEV ransomware
- CVE-2020-2021 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1636
- CVE-2021-21311 KEV
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2023-4911 KEV
- CVE-2024-2617
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Havex
-
Energetic Bear, Dragonfly - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Energetic Bear, Dragonfly - Threat Group Cards: A Threat Actor Encyclopedia
-
Berserk Bear, Dragonfly 2.0 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Berserk Bear, Dragonfly 2.0 - Threat Group Cards: A Threat Actor Encyclopedia
Show all 138 reports Show fewer
-
Havex RAT - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Havex RAT - Threat Group Cards: A Threat Actor Encyclopedia
-
Full Disclosure of Havex Trojans.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Full Disclosure of Havex Trojans.pdf
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
-
TTPs of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector (AA22-083A).pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TTPs of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector (AA22-083A).pdf
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-083A) Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector
-
UK exposes Russian spy agency behind cyber incidents
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UK exposes Russian spy agency behind cyber incidents
-
Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
-
Anticipating Cyber Threats as the Ukraine Crisis Escalates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anticipating Cyber Threats as the Ukraine Crisis Escalates
-
Bear in the Net- A Network-Focused Perspective on Berserk Bear
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bear in the Net- A Network-Focused Perspective on Berserk Bear
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
Extrapolating Adversary Intent Through Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Extrapolating Adversary Intent Through Infrastructure
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Enigmatic Energetic Bear
-
The Russian Hackers (BERSERK BEAR) Playing 'Chekhov's Gun' With US Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Russian Hackers (BERSERK BEAR) Playing 'Chekhov's Gun' With US Infrastructure
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA20-296A)- Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets
-
Industry alert pins state, local government hacking on suspected Russian group (Temp.Isotope)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industry alert pins state, local government hacking on suspected Russian group (Temp.Isotope)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
Russian Cyber Attack Campaigns and Actors - Threat Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack Campaigns and Actors - Threat Research
-
German intelligence agencies warn of Russian hacking threats to critical infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor German intelligence agencies warn of Russian hacking threats to critical infrastructure
-
The ICS Threat Landscape and Activity Groups
The original link failed its last check. Original publisher Detailsfor The ICS Threat Landscape and Activity Groups
-
North American Electric Cyber Threat Perspective
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North American Electric Cyber Threat Perspective
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT Trends Report Q2 2018
-
Mapping the connections inside Russia APT Ecosystem
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mapping the connections inside Russia APT Ecosystem
-
Dragos - Global Oil and Gas Cyber Threat Perspctive
The original link failed its last check. Original publisher Detailsfor Dragos - Global Oil and Gas Cyber Threat Perspctive
-
Updated Karagany Malware Targets Energy Sector
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Updated Karagany Malware Targets Energy Sector
-
Resurgent Iron Liberty Targeting Energy Sector
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Resurgent Iron Liberty Targeting Energy Sector
-
Resurgent Iron Liberty Targeting Energy Sector
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Resurgent Iron Liberty Targeting Energy Sector
-
The original link failed its last check. Original publisher Detailsfor Sample-WorldView-Report.pdf
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Allanite
-
API Hashing Tool, Imagine That
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor API Hashing Tool, Imagine That
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
yir-ics-activity-groups-threat-landscape-2018.pdf
The original link failed its last check. Original publisher Detailsfor yir-ics-activity-groups-threat-landscape-2018.pdf
-
The APT Chronicles_December 2018 edition
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The APT Chronicles_December 2018 edition
-
Russian Hackers Haven't Stopped Probing the US Power Grid (Temp.Isotope)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Hackers Haven't Stopped Probing the US Power Grid (Temp.Isotope)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends Report Q2 2018
-
Who's who in the Zoo - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Who's who in the Zoo - Securelist
-
Energetic Bear/Crouching Yeti: attacks on servers - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Energetic Bear/Crouching Yeti: attacks on servers - Securelist
-
Energetic Bear-Crouching Yeti- attacks on servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Energetic Bear-Crouching Yeti- attacks on servers
-
Energetic Bear/Crouching Yeti: attacks on servers
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Energetic Bear/Crouching Yeti: attacks on servers
-
Industrial Control System Threats
The original link failed its last check. Original publisher Detailsfor Industrial Control System Threats
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation_Dragonfly_Analysis
-
New Insights into Energetic Bear’s Watering Hole Cyber Attacks on Turkish Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Insights into Energetic Bear’s Watering Hole Cyber Attacks on Turkish Critical Infrastructure
-
New Insights into Energetic Bear's Attacks on Turkish Critical Infrastructure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Insights into Energetic Bear's Attacks on Turkish Critical Infrastructure
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog Dragonfly 2
-
Dragonfly: Western energy sector targeted by sophisticated attack group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Dragonfly: Western energy sector targeted by sophisticated attack group
-
intelligence-games-in-the-power-grid-2016
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor intelligence-games-in-the-power-grid-2016
-
Crouching Yeti (Energetic Bear) Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Crouching Yeti (Energetic Bear) Malware
-
GRIZZLY STEPPE - Russian Malicious Cyber Activity
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor GRIZZLY STEPPE - Russian Malicious Cyber Activity
-
DHS-NCCIC - Malware Trends.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DHS-NCCIC - Malware Trends.pdf
-
On the StrongPity Waterhole Attacks - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor On the StrongPity Waterhole Attacks - Securelist
-
On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
-
On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 人面狮行动
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Defending Against the Dragonfly Cyber Security Attacks v3.0.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Defending Against the Dragonfly Cyber Security Attacks v3.0.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Darkhotel APT
-
Full Disclosure of Havex Trojans
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Full Disclosure of Havex Trojans
-
Full Disclosure of Havex Trojans - NETRESEC Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Full Disclosure of Havex Trojans - NETRESEC Blog
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SCADA Network Forensics.pdf
-
EB - Yeti July 2014 - Public.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor EB - Yeti July 2014 - Public.docx
-
Kaspersky_Lab_crouching_yeti_appendixes_eng_final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Kaspersky_Lab_crouching_yeti_appendixes_eng_final
-
Dragonfly: Cyberespionage Attacks Against Energy Suppliers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dragonfly: Cyberespionage Attacks Against Energy Suppliers
-
Security Response - Dragonfly v1.0.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Security Response - Dragonfly v1.0.pdf
-
Security Response - Dragonfly v1.2.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Security Response - Dragonfly v1.2.pdf
-
Iran and Russia blamed for state-sponsored espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for state-sponsored espionage
-
Iran and Russia blamed for statesponsored espionage
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for statesponsored espionage
-
Iran and Russia blamed for state-sponsored espionage
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for state-sponsored espionage
Newest first. Details opens the report in Explore.