← All actors Recent activity

Dragonfly G0035

ENERGETICBEAR · crouching yeti · dragonfly · iron liberty · tg-4192

Indicators
7
Source reports
4
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20192020

Overview 7 indicators

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.

domain5G0035-domain.txt
url2G0035.json

Techniques 56 ATT&CK

Open in ATT&CK Navigator → or download the layer (56 techniques, layer 4.5)

Software 10

Principal sources 4 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 7 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 1 domain, 2 url6 yrs ago

    securelist.com/energetic-bear-crouching-yeti/85345 · virustotal.com/gui/ip-address/155.207.63.4/relations · virustotal.com/gui/ip-address/51.159.28.101/relations

    domainlite.ultralitedesigns.com
    urlhttp://155.207.63.4
    urlhttp://51.159.28.101

  2. 4 domain7 yrs ago

    lab52.io/blog/the-geopolitical-and-potential-cyb…

    ecco0.b13x.org
    kanri.rbridal.net
    satanal.info
    tureg.info

Further reading 19