Home/Threat Actor/Dragonfly
Threat Actor

Dragonfly

dragonfly_energetic_bear · russia · active since 2010

Dragonfly (Energetic Bear / Berserk Bear / Crouching Yeti / Iron Liberty / Ghost Blizzard / G0035) is a Russian FSB Center 16 cyber- espionage and critical-infrastructure-targeting cluster active since 2010 and indicted by US DOJ in 2022 (Akulov, Gavrilov, Tyukov), responsible for over a decade of sustained operations against US, UK, and European energy, nuclear, water, and ICS-vendor-supply-chain targets, including the Wolf Creek nuclear targeting, the 2011-2014 Havex / OPC-scanning ICS reconnaissance campaign disclosed by Symantec and F-Secure, the 2015-2017 Dragonfly 2.0 watering-hole and forced-authentication campaign against Western electric utilities, and the 2020 SLTT-government and aviation campaign disclosed by CISA AA20-296A.

russia confidence: high 19 aliases MITRE ATT&CK G0035 ↗

Profile

Dragonfly (also tracked as Energetic Bear, Crouching Yeti, Berserk Bear, Iron Liberty, Ghost Blizzard, TEMP.Isotope, Allanite, and MITRE ATT&CK G0035) is a Russian state-sponsored cyber-espionage and critical-infrastructure-targeting cluster active since at least 2010. The cluster is attributed to Russia's Federal Security Service (FSB), specifically Center 16 (the 16th Center for Radio-Electronic Intelligence, Military Unit 71330), the same FSB directorate that operates the Turla espionage cluster, though Dragonfly is operationally distinct and ICS/OT-focused. The 24 March 2022 unsealing of a US District of Kansas indictment named three FSB Center 16 officers, Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, and Marat Valeryevich Tyukov, for a 2012-2017 campaign against more than 17,000 devices in 135 countries, including the Wolf Creek Nuclear Operating Corporation in Burlington, Kansas.

This indictment is the canonical public attribution. A separate same-day indictment in DC named Evgeny Viktorovich Gladkikh of TsNIIKhM (a Russian Ministry of Defense research institute) for the 2017 Triton / TRISIS attack on a Saudi petrochemical plant, that activity is the separate Xenotime cluster and must not be conflated with Dragonfly. Operationally Dragonfly is defined by sustained, methodical targeting of energy-sector business networks (electric utilities, oil and gas, nuclear, water and wastewater) and the ICS-vendor supply-chain.

The cluster's earliest publicly-documented operations (the 2011-2014 "Phase 1" Energetic Bear campaign) included trojanized ICS-software installers distributed via the compromised websites of three European ICS vendors (eWON / Talk2M, MB Connect Line / mbCONFTOOL, and MESA Imaging / SwissRanger), delivering the Havex backdoor (Backdoor.Oldrea) which performed OPC-protocol network reconnaissance against operational technology environments. That OPC scanning behavior was distinctive evidence of ICS-focused intent and remains one of the cluster's signature behaviors in retrospective analysis. The 2015-2017 "Dragonfly 2.0" campaign disclosed by Symantec in October 2017 marked a sustained second wave of operations against US, UK, Swiss, and Turkish electric utilities, including documented penetration of operational network segments and screen captures of HMI (human-machine interface) systems inside US energy networks.

Dragonfly 2.0 popularized the cluster's use of forced-authentication tradecraft (T1187): embedding single-pixel images referencing attacker-controlled SMB servers in maldoc lures and compromised energy-industry websites to harvest Net-NTLM hashes for offline cracking. From 2018 forward, operational signatures more often appear under the "Berserk Bear" label (per CrowdStrike) and "Iron Liberty" (Secureworks) and Microsoft's "Ghost Blizzard" naming. CISA's TA18- 074A (March 2018) provided the first explicit US-government attribution of the cluster's pattern of activity to the Russian state.

CISA / FBI AA20-296A (October 2020) disclosed successful compromise of two US State, Local, Tribal, and Territorial (SLTT) government networks during the 2020 US election cycle via exploitation of Citrix (CVE-2019-19781), Exchange (CVE-2020-0688), Fortinet (CVE-2018-13379), and Cisco router vulnerabilities, paired with password spraying. The cluster's toolkit is comparatively pragmatic and not heavy on bespoke implants, Havex (Backdoor.Oldrea) and Karagany (Trojan. Karagany) are the most-cited legacy implants, along with Heriplor (a backdoor unique to the cluster) and Goodor, with substantial reliance on living-off-the-land tooling (PowerShell, mshta, schtasks, rundll32, certutil) and open-source credential-access utilities (Mimikatz, Hydra, CrackMapExec, Impacket / secretsdump, PsExec).

Public attribution and the 2022 indictment have not produced a visible operational pause. As of the project handoff date, Dragonfly's operators are assessed by CISA, NCSC UK, and partner agencies to remain active against Western critical infrastructure, although 2023-2025 public reporting attributes much of the visible Russian state-aligned ICS-targeting activity to Sandworm or to less-specific "Russian state-aligned" framing rather than to the Dragonfly cluster by name. Dragos's ALLANITE designation tracks the energy-grid-focused subset of the activity.

Aliases

19
dragonflydragonfly 2.0energetic bearenergetic_bearberserk bearberserk_bearcrouching yeticrouching_yetiiron libertybrominekoala teamghost blizzardallanitecastletemp.isotopetemp_isotopetg-4192g0035apt-c-25

MITRE ATT&CK aliases

1
Additional names MITRE lists for G0035.
DYMALLOY

Notable Campaigns

8
2022-2025Continued Russian State-Aligned ICS Targeting (2022-2025)
2022DOJ FSB Center 16 Indictment Unsealing (March 24, 2022)
2020Berserk Bear US SLTT Government and Aviation Targeting (CISA AA20-296A, October 2020)
2018CISA TA18-074A, Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors (March 2018)
2017Wolf Creek Nuclear Operating Corporation Targeting (2017)
2015-2017Dragonfly 2.0, US and EU Energy Sustained Campaign (2015-2017)
2014Symantec Dragonfly Disclosure (June 2014)
2011-2014Energetic Bear Phase 1, ICS Reconnaissance (2011-2014)

Attribution & Reporting

Attributed by
US Department of JusticeFBICISANSAUS Department of StateUS Department of the Treasury OFACUK NCSCUK FCDOCouncil of the European UnionSymantecMandiant / FireEyeCrowdStrikeSecureworksMicrosoftDragosKasperskyESETTalosTrend MicroRecorded Future Insikt GroupF-Secure / WithSecure
Key reporting
reportSymantec: Dragonfly, Western Energy Companies Under Sabotage Threat (June 30, 2014)
reportF-Secure: Havex Hunts for ICS/SCADA Systems (June 23, 2014)
reportF-Secure / WithSecure: Backdoor:W32/Havex Whitepaper (2014)
reportKaspersky GReAT: Energetic Bear / Crouching Yeti, Investigation of a Successful APT Campaign (July 2014)
reportSymantec: Dragonfly, Western Energy Sector Targeted by Sophisticated Attack Group (October 20, 2017)
reportCISA / DHS / FBI TA18-074A: Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors (March 15, 2018)
reportCrowdStrike: From RSA to IRON TWILIGHT, Berserk Bear's Busy 2017 (2017)
reportCrowdStrike: Who is BERSERK BEAR? (2020)
reportSecureworks: Threat Profile, IRON LIBERTY
reportCisco Talos: Template Injection Attacks Bypass Security Solutions (July 2017)
reportESET: Havex Targets Industrial Control Systems (July 2014)
reportCISA / FBI AA20-296A: Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets (October 22, 2020)
reportDragos: ALLANITE Threat Group Profile
reportRecorded Future Insikt Group: Russian Cyber Activity Against the US Energy Sector
reportUS DOJ: Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure (March 24, 2022)
reportUS DOJ District of Kansas Indictment, USA v. Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, Marat Valeryevich Tyukov (August 26, 2021, unsealed March 24, 2022)
reportUS Treasury OFAC SDN Designations Concurrent with 2022 Indictment Unsealing
reportUS Department of State Rewards-for-Justice, Bounties for Information on FSB Center 16 Officers (March 2022)
reportCISA / NSA / FBI / DOE / EPA / NCSC AA22-110A: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure (April 20, 2022)
reportMandiant: Russian Targeting of Government and Business (2022)
reportMalpedia Actor Profile: Energetic Bear / Dragonfly
reportMITRE ATT&CK Group G0035, Dragonfly

Operational

State sponsor

Russian FSB Center 16 (Russian Federal Security Service, 16th Center for Radio-Electronic Intelligence, Military Unit 71330). The same directorate that runs the Turla cyber-espionage cluster.

Dragonfly is operationally distinct and focuses on industrial control system (ICS) and energy-sector targeting. Attribution was substantively confirmed by the US Department of Justice on 24 March 2022 with the unsealing of a 26 August 2021 indictment in the District of Kansas naming three FSB Center 16 officers, Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, and Marat Valeryevich Tyukov, for a multi-year campaign (2012-2017) against more than 17,000 unique devices in the United States and abroad, including the targeting of the Wolf Creek Nuclear Operating Corporation in Burlington, Kansas. A separate indictment unsealed the same day named Evgeny Viktorovich Gladkikh of TsNIIKhM (a Russian Ministry of Defense research institute) for the 2017 Triton / TRISIS attack on a Saudi petrochemical plant, that is a distinct cluster (Xenotime) and must not be conflated with Dragonfly. Concurrent US Treasury OFAC SDN designations, and parallel UK NCSC and EU sanctions, support the FSB Center 16 attribution.

Motivations
espionage, intelligence_gathering, critical_infrastructure_targeting, ics_ot_reconnaissance, pre_positioning
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MESHAGENT ABUSEMSHTASECRETSDUMPSMB RELAY TOOLINGSSHD BACKDOORSYSGET
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin