news.mlab.sh
Threat intelligence
Threat actor

Energetic Bear

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Russia
Targeted countries
Russia
TLP
WHITE

Dragonfly is a cyberespionage group that has been active since at least 2011. They initially targeted defense and aviation companies but shifted to focus on the energy sector in early 2013. They have also targeted companies related to industrial control systems. According to Kaspersky, Crouching Yeti has been operating since at least 2010 and has infected roughly 2,800 targets in 38 countries, and in industries as diverse as education and pharmaceuticals. A similar group emerged in 2015 and was identified by Symantec as Berserk Bear, Dragonfly 2.0. There is debate over the extent of the overlap between Dragonfly and Dragonfly 2.0, but there is sufficient evidence to lead to these being tracked as two separate groups.

Also known as

ATK 6Berserk BearBlue KrakenBromineCrouching YetiDragonflyDYMALLOYElectrumEnergetic BearG0035Ghost BlizzardGroup 24Iron LibertyITG15Koala TeamTEMP.IsotopeTG-4192

Vulnerabilities exploited

Tooling and malware

Backdoor.OldreaTrojan.KaraganyCrackMapExecImpacketMCMDMimikatzNetnetshPsExecReg

MITRE ATT&CK techniques

T1005 Data from Local SystemT1113 Screen CaptureT1560 Archive Collected DataT1105 Ingress Tool TransferT1110 Brute ForceT1187 Forced AuthenticationT1112 Modify RegistryT1686 Disable or Modify System FirewallT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1083 File and Directory DiscoveryT1135 Network Share DiscoveryT1059 Command and Scripting InterpreterT1203 Exploitation for Client ExecutionT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1210 Exploitation of Remote ServicesT1133 External Remote ServicesT1078 Valid AccountsT1221 Template Injection

Coverage 3