Overview 7 indicators
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.
| domain | 5 | G0035-domain.txt |
| url | 2 | G0035.json |
Techniques 56 ATT&CK
Open in ATT&CK Navigator → or download the layer (56 techniques, layer 4.5)
- T1003.002 Security Account Manager
- T1003.003 NTDS
- T1003.004 LSA Secrets
- T1005 Data from Local System
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.001 Remote Desktop Protocol
- T1033 System Owner/User Discovery
- T1036.010 Masquerade Account Name
- T1053.005 Scheduled Task
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.006 Python
- T1069.002 Domain Groups
- T1070.004 File Deletion
- T1071.002 File Transfer Protocols
- T1074.001 Local Data Staging
- T1078 Valid Accounts
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1098.007 Additional Local or Domain Groups
- T1105 Ingress Tool Transfer
- T1110 Brute Force
- T1110.002 Password Cracking
- T1112 Modify Registry
- T1113 Screen Capture
- T1114.002 Remote Email Collection
- T1133 External Remote Services
- T1135 Network Share Discovery
- T1136.001 Local Account
- T1187 Forced Authentication
- T1189 Drive-by Compromise
- T1190 Exploit Public-Facing Application
- T1195.002 Compromise Software Supply Chain
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1210 Exploitation of Remote Services
- T1221 Template Injection
- T1505.003 Web Shell
- T1547.001 Registry Run Keys / Startup Folder
- T1560 Archive Collected Data
- T1564.002 Hidden Users
- T1566.001 Spearphishing Attachment
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1584.004 Server
- T1588.002 Tool
- T1591.002 Business Relationships
- T1595.002 Vulnerability Scanning
- T1598.002 Spearphishing Attachment
- T1598.003 Spearphishing Link
- T1608.004 Drive-by Target
- T1685.005 Clear Windows Event Logs
- T1686 Disable or Modify System Firewall
Software 10
Principal sources 4 reports
Ranked by how many of this actor's indicators each report brought in.
- 4lab52.io/blog/the-geopolitical-and-potential-cyb…
- 3securelist.com/energetic-bear-crouching-yeti/85345
- 3virustotal.com/gui/ip-address/155.207.63.4/relations
- 3virustotal.com/gui/ip-address/51.159.28.101/relations
Timeline 7 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
securelist.com/energetic-bear-crouching-yeti/85345 · virustotal.com/gui/ip-address/155.207.63.4/relations · virustotal.com/gui/ip-address/51.159.28.101/relations
domain lite.ultralitedesigns.com url http://155.207.63.4 url http://51.159.28.101 -
lab52.io/blog/the-geopolitical-and-potential-cyb…
ecco0.b13x.org kanri.rbridal.net satanal.info tureg.info
Further reading 19
- fortune.com/2017/09/06/hack-energy-grid-symantec
- attack.mitre.org/groups/G0035
- community.broadcom.com/symantecenterprise/communities/communit…
- docs.broadcom.com/doc/dragonfly_threat_against_western_en…
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- symantec-enterprise-blogs.security.com/blogs/threat-intelligence/dragonfly-ene…
- vblocalhost.com/uploads/VB2021-Slowik.pdf
- cisa.gov/uscert/ncas/alerts/aa20-296a#revisions
- dragos.com/threat/dymalloy
- gov.uk/government/publications/russias-fsb-mal…
- justice.gov/opa/pr/four-russian-government-employee…
- mandiant.com/resources/ukraine-crisis-cyber-threats
- secureworks.com/research/mcmd-malware-analysis
- secureworks.com/research/resurgent-iron-liberty-targeti…
- secureworks.com/research/updated-karagany-malware-targe…
- virustotal.com/gui/ip-address/51.159.28.101/relations
- virustotal.com/gui/ip-address/155.207.63.4/relations
- lab52.io/blog/the-geopolitical-and-potential-cyb…
- securelist.com/energetic-bear-crouching-yeti/85345