All actors

Dragonfly

Also reported as TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti and 4 other names.

Reports
138
Last reported
Known CVEs
101
Techniques in ATT&CK
58
ID
G0035
Sources
ATT&CK
Merge evidence
0 alias matches

Reports per quarter

  1. 2014 Q1: 3 reports
  2. 2014 Q2: 2 reports
  3. 2014 Q3: 4 reports
  4. 2014 Q4: 8 reports
  5. 2015 Q1: 1 report
  6. 2015 Q2: no reports
  7. 2015 Q3: no reports
  8. 2015 Q4: no reports
  9. 2016 Q1: 3 reports
  10. 2016 Q2: 1 report
  11. 2016 Q3: 1 report
  12. 2016 Q4: 8 reports
  13. 2017 Q1: no reports
  14. 2017 Q2: 2 reports
  15. 2017 Q3: 4 reports
  16. 2017 Q4: 4 reports
  17. 2018 Q1: 2 reports
  18. 2018 Q2: 6 reports
  19. 2018 Q3: 2 reports
  20. 2018 Q4: 4 reports
  21. 2019 Q1: 8 reports
  22. 2019 Q2: 3 reports
  23. 2019 Q3: 4 reports
  24. 2019 Q4: 2 reports
  25. 2020 Q1: 2 reports
  26. 2020 Q2: 3 reports
  27. 2020 Q3: 2 reports
  28. 2020 Q4: 8 reports
  29. 2021 Q1: 2 reports
  30. 2021 Q2: 2 reports
  31. 2021 Q3: 1 report
  32. 2021 Q4: 1 report
  33. 2022 Q1: 9 reports
  34. 2022 Q2: 10 reports
  35. 2022 Q3: 2 reports
  36. 2022 Q4: no reports
  37. 2023 Q1: 1 report
  38. 2023 Q2: no reports
  39. 2023 Q3: no reports
  40. 2023 Q4: 1 report
  41. 2024 Q1: no reports
  42. 2024 Q2: no reports
  43. 2024 Q3: 1 report
  44. 2024 Q4: no reports
  45. 2025 Q1: no reports
  46. 2025 Q2: no reports
  47. 2025 Q3: no reports
  48. 2025 Q4: no reports
  49. 2026 Q1: 2 reports
  50. 2026 Q2: 19 reports
Dated reports, 2014 Q1 to 2026 Q2.

Techniques seen in the last two years

Show all 90 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 101 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Havex

    date ORKL added it fromORKL

Show all 138 reports Show fewer
  1. Full Disclosure of Havex Trojans.pdf

    date ORKL added it fromORKL

  2. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  3. Russian State-Sponsored and Criminal Cyber .pdf

    file creation date fromORKL

  4. UK exposes Russian spy agency behind cyber incidents

    date in the title fromORKL

  5. Anticipating Cyber Threats as the Ukraine Crisis Escalates

    date in the title fromORKL

  6. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  7. Russian cyber attack campaigns and actors

    date in the title fromORKL

  8. Extrapolating Adversary Intent Through Infrastructure

    date in the title fromORKL

  9. The Enigmatic Energetic Bear

    date in the title fromORKL

  10. ESET_Threat_Report_Q22020

    file creation date fromORKL

  11. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  12. Russian Cyber Attack Campaigns and Actors - Threat Research

    file creation date fromORKL

  13. North American Electric Cyber Threat Perspective

    Malpedia library date fromORKL

  14. APT Trends Report Q2 2018

    file creation date Kaspersky fromORKL

  15. Mapping the connections inside Russia APT Ecosystem

    file creation date fromORKL

  16. Updated Karagany Malware Targets Energy Sector

    date in the title fromORKL

  17. Resurgent Iron Liberty Targeting Energy Sector

    date in the title fromORKL

  18. Resurgent Iron Liberty Targeting Energy Sector

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  19. Sample-WorldView-Report.pdf

    file creation date fromORKL

  20. rpt-mtrends-2019.pdf

    file creation date fromORKL

  21. Allanite

    date in the title fromORKL

  22. API Hashing Tool, Imagine That

    date in the title fromORKL

  23. Report2019GlobalThreatReport

    file creation date fromORKL

  24. rpt-mtrends-2019

    file creation date fromORKL

  25. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  26. The APT Chronicles_December 2018 edition

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  27. APT Trends Report Q2 2018

    date in the title fromORKL

  28. BfV Cyber-Brief Nr. 01/2018

    file creation date Bundesamt für Verfassungsschutz fromORKL

  29. Who's who in the Zoo - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  30. Energetic Bear/Crouching Yeti: attacks on servers - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  31. Energetic Bear-Crouching Yeti- attacks on servers

    date in the title fromORKL

  32. Energetic Bear/Crouching Yeti: attacks on servers

    file creation date Kaspersky fromORKL

  33. Industrial Control System Threats

    Malpedia library date Dragos fromORKL

  34. Operation_Dragonfly_Analysis

    date in the CCS '25 data McAfee fromORKLCCS '25 data

  35. New Insights into Energetic Bear's Attacks on Turkish Critical Infrastructure

    date in the CCS '25 data RiskIQ fromORKLCCS '25 data

  36. blog Dragonfly 2

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  37. intelligence-games-in-the-power-grid-2016

    file creation date fromORKL

  38. Crouching Yeti (Energetic Bear) Malware

    date in the title fromORKL

  39. GRIZZLY STEPPE - Russian Malicious Cyber Activity

    date in the CCS '25 data US-CERT fromORKLCCS '25 data

  40. DHS-NCCIC - Malware Trends.pdf

    file creation date fromORKL

  41. On the StrongPity Waterhole Attacks - Securelist

    file creation date fromORKL

  42. 人面狮行动

    date in the CCS '25 data F-Secure fromORKLCCS '25 data

  43. PowerPoint Presentation

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  44. Global Threat Intel Report

    Malpedia library date Crowdstrike fromORKL

  45. The Darkhotel APT

    date in the title fromORKL

  46. Full Disclosure of Havex Trojans

    date in the title fromORKL

  47. Full Disclosure of Havex Trojans - NETRESEC Blog

    date in the CCS '25 data Netresec fromORKLCCS '25 data

  48. SCADA Network Forensics.pdf

    file creation date fromORKL

  49. EB - Yeti July 2014 - Public.docx

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  50. Kaspersky_Lab_crouching_yeti_appendixes_eng_final

    file creation date Kaspersky fromORKL

  51. Dragonfly: Cyberespionage Attacks Against Energy Suppliers

    Malpedia library date Symantec fromORKLCCS '25 data

  52. Security Response - Dragonfly v1.0.pdf

    file creation date fromORKL

  53. Security Response - Dragonfly v1.2.pdf

    file creation date fromORKL

  54. Iran and Russia blamed for state-sponsored espionage

    date in the title fromORKL

  55. Iran and Russia blamed for statesponsored espionage

    Malpedia library date fromORKL

  56. Iran and Russia blamed for state-sponsored espionage

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.