G0035 · 64 ATT&CK techniques · 2 correlated reports

Dragonfly

Aliases: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.

Open interactive actor investigation

ATT&CK techniques

T1560
Archive Collected Data
T1113
Screen Capture
T1564.002
Hidden Users
T1505.003
Web Shell
T1204.002
Malicious File
T1591.002
Business Relationships
T1078
Valid Accounts
T1016
System Network Configuration Discovery
T1584.004
Server
T1083
File and Directory Discovery
T1136.001
Local Account
T1221
Template Injection
T1203
Exploitation for Client Execution
T1110.002
Password Cracking
T1608.004
Drive-by Target
T1562.004
Disable or Modify System Firewall
T1012
Query Registry
T1566.001
Spearphishing Attachment
T1189
Drive-by Compromise
T1583.001
Domains
T1003.002
Security Account Manager
T1598.002
Spearphishing Attachment
T1070.001
Clear Windows Event Logs
T1005
Data from Local System
T1070.004
File Deletion
T1059
Command and Scripting Interpreter
T1112
Modify Registry
T1588.002
Tool
T1195.002
Compromise Software Supply Chain
T1036.010
Masquerade Account Name
T1003.003
NTDS
T1098.007
Additional Local or Domain Groups
T1583.003
Virtual Private Server
T1059.003
Windows Command Shell
T1071.002
File Transfer Protocols
T1598.003
Spearphishing Link
T1053.005
Scheduled Task
T1069.002
Domain Groups
T1114.002
Remote Email Collection
T1595.002
Vulnerability Scanning
T1547.001
Registry Run Keys / Startup Folder
T1105
Ingress Tool Transfer
T1133
External Remote Services
T1003.004
LSA Secrets
T1190
Exploit Public-Facing Application
T1135
Network Share Discovery
T1110
Brute Force
T1021.001
Remote Desktop Protocol
T1187
Forced Authentication
T1033
System Owner/User Discovery
T1074.001
Local Data Staging
T1059.001
PowerShell
T1210
Exploitation of Remote Services
T1059.006
Python
T1018
Remote System Discovery
T1087.002
Domain Account
T1547.009
Shortcut Modification
T1566
Phishing
T1136
Create Account
T1070
Indicator Removal
T1114
Email Collection
T1036
Masquerading
T1003
OS Credential Dumping
T1053
Scheduled Task/Job

Correlated CTI and IR reports

Continue the investigation