Home/Threat Actor/GANANITE
Threat Actor

GANANITE

gananite · state_actor_dragos_tracked_cis_central_asia_espionage_focus_2023_disclosed · active since 2023-01

GANANITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report focusing on espionage and data theft targeting critical infrastructure and government entities in the Commonwealth of Independent States (CIS) and Central Asian nations per Dragos canonical threat profile ("GANANITE targets critical infrastructure and government entities in the Commonwealth of Independent States and Central Asian nations, focusing on espionage and data theft with the possibility of handing off initial access to other threat groups") with multi-sector European + Eurasian targeting expansion per CSO Online + Dragos 2024 + 2025 Year-in-Review continued tracking.

state-actor attribution via Dragos canonical 2023 Year-in-Review GANANITE disclosure + 2024 + 2025 Year-in-Review continued tracking + CSO Online canonical Three new advanced threat groups 2024 coverage + Dragos threat groups summary 2025 victim-impersonation tradecraft addition + Dragos MITRE ATT&CK for ICS framework taxonomy listing.

honest attribution caveat Dragos doesn't publicly attribute GANANITE to specific nation-state consistent with canonical no-public-nation-attribution policy.

standalone cluster paralleling laurionite + bauxite + kostovite in v0.1.172 OT/ICS Dragos-newer- taxonomy actor cluster cell continuation extending v0.1.166 chernovite/kamacite/raspite/ covellite classic Dragos taxonomy cell; operational target profile signature CIS + Central Asia geographic focus per Dragos + European oil and gas company ICS operations management key personnel targeting per CSO Online ("GANANITE has been observed conducting multiple attacks against key personnel related to ICS operations management in a prominent European oil and gas company") + Turkey + Azerbaijan rail organizations regional geopolitical context (Armenia-Azerbaijan conflict parallel to STIBNITE Azerbaijan focus) + multiple transportation and logistics companies + automotive machinery company + at least one European government entity overseeing public water utilities.

operational attack architecture: (1) cluster-defining CIS + Central Asia geographic focus distinguishing GANANITE from US-focused ICS clusters like CHERNOVITE + KOSTOVITE + BAUXITE.

(2) cluster-defining European oil and gas ICS operations management key personnel targeting tradecraft with social-engineering focus on individuals managing ICS systems rather than direct ICS network compromise.

(3) cluster- defining Turkey + Azerbaijan rail organizations targeting signature consistent with regional geopolitical context (Armenia-Azerbaijan conflict paralleling STIBNITE 2020 Azerbaijan wind turbine targeting pattern)

(4) cluster-defining multi- sector targeting with transportation + logistics + automotive machinery + European government water utilities oversight reflecting broad critical- infrastructure intelligence collection objectives; (5) cluster-defining victim impersonation tradecraft per Dragos 2025 threat groups summary ("GANANITE: Impersonates victims, exploits vulnerabilities, targets internet-exposed endpoints, and exfiltrates data") establishing social-engineering + identity-spoofing as operational signature.

(6) cluster-defining internet-exposed endpoint exploitation tradecraft per Dragos 2025 with vulnerability exploitation against publicly-accessible assets.

(7) cluster- defining initial access handoff potential signature paralleling KAMACITE access-enablement- team operational model per Dragos ("focusing on espionage and data theft with the possibility of handing off initial access to other threat groups... Industrial organizations in Europe and Central Asia face a significant risk from GANANITE due to their initial intrusion capabilities, post- compromise espionage TTPs, and intellectual property theft, all of which can be used in follow-on attacks against the victim organizations"); (8) cluster-defining ICS Cyber Kill Chain Stage 1 efficient multi-phase utilization per Dragos ("their assessed capabilities show efficient use of multiple phases across Stage 1 of the ICS Kill Chain") with no OT-network movement observed consistent with Stage 1 focus.

(9) signature intellectual property theft objective expansion from base espionage + data theft per Dragos; (10) signature Dragos 2025 OT Cybersecurity Year in Review continued tracking establishing operational continuity + active-tracking-status; (11) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference- status alongside other Dragos-tracked clusters; cluster fills the Dragos-GANANITE-Activity-Group + CIS-Central-Asia-espionage-targeting + European- oil-and-gas-key-personnel-ICS-operations + Turkey- Azerbaijan-rail-organizations + transportation- logistics-automotive-machinery-multi-sector + European-government-water-utilities-oversight + victim-impersonation-tradecraft + internet- exposed-endpoint-targeting + ICS-Cyber-Kill-Chain- Stage-1-efficient + initial-access-handoff- potential + 2023-Dragos-Year-in-Review-disclosure position in OT/ICS Dragos-newer-taxonomy actor cluster cell.

canonical illustration of CIS + Central Asia espionage-focused ICS Activity Group + European oil and gas key-personnel targeting + Turkey/Azerbaijan rail + multi-sector transportation + automotive + water utilities targeting + victim impersonation tradecraft + initial-access-handoff KAMACITE-parallel operational pattern cited in essentially all subsequent Dragos-taxonomy newer- cluster industry analyses through 2023-2026 period.

state_actor_dragos_tracked_cis_central_asia_espionage_focus_2023_disclosed confidence: high 17 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

GANANITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report focusing on espionage and data theft targeting critical infrastructure and government entities in the Commonwealth of Independent States (CIS) and Central Asian nations + European oil and gas + Turkey/Azerbaijan rail + transportation/ logistics + automotive machinery + European government water utilities oversight. State-actor attribution via Dragos canonical 2023 Year-in-Review GANANITE disclosure + 2024 + 2025 Year-in-Review continued tracking + CSO Online industry coverage. Standalone cluster paralleling laurionite + bauxite + kostovite in v0.1.172 OT/ICS Dragos- newer-taxonomy actor cluster cell continuation.

Operational target profile
  • CIS + Central Asia signature.
  • European oil and gas key-personnel ICS operations management.
  • Turkey + Azerbaijan rail signature.
  • Transportation + logistics + automotive machinery.
  • European government public water utilities oversight entity Operational attack architecture: (1) CIS + Central Asia geographic focus (cluster-defining) (2) European oil & gas ICS operations management personnel targeting (cluster-defining) (3) Turkey + Azerbaijan rail organizations regional context (cluster-defining) (4) Victim impersonation tradecraft (cluster- defining 2025 update) (5) Internet-exposed endpoint exploitation (cluster-defining 2025 update) (6) Initial access handoff potential KAMACITE- parallel pattern (cluster-defining) (7) ICS Cyber Kill Chain Stage 1 efficient multi-phase utilization (cluster-defining) The cluster fills the Dragos-GANANITE-Activity- Group + CIS-Central-Asia-espionage-targeting + European-oil-and-gas-key-personnel-ICS-operations + Turkey-Azerbaijan-rail-organizations + transportation- logistics-automotive-machinery-multi-sector + European-government-water-utilities-oversight + victim-impersonation-tradecraft + internet- exposed-endpoint-targeting + ICS-Cyber-Kill-Chain- Stage-1-efficient + initial-access-handoff- potential + 2023-Dragos-Year-in-Review-disclosure position in OT/ICS Dragos-newer-taxonomy actor cluster cell.

Aliases

17
gananitegananite activity groupdragos gananite trackinggananite cis central asia espionage targetinggananite commonwealth of independent states critical infrastructuregananite european oil and gas key personnel ics operationsgananite turkey rail organizations targetinggananite azerbaijan rail organizations targetinggananite transportation logistics multi-company targetinggananite automotive machinery company targetinggananite european government public water utilities oversightgananite ics cyber kill chain stage 1 efficientgananite initial access handoff potential other threat groupsgananite victim impersonation tradecraftgananite internet-exposed endpoint targetinggananite intellectual property theft signaturegananite 2023 dragos year-in-review disclosure

Notable Campaigns

9
2025GANANITE 2025 Victim Impersonation + Internet-Exposed Endpoint Tradecraft Signature
2025GANANITE 2025 Dragos Central Asia Tracking Continuation Signature
2023-2026Continued Industry Reference Status (2023-2026)
2023-2025GANANITE CIS + Central Asia Espionage Focus Signature
2023-2025GANANITE Initial Access Handoff Potential to Other Threat Groups Signature (KAMACITE-Parallel)
2023-2024GANANITE European Oil & Gas ICS Operations Management Personnel Targeting Signature
2023-2024GANANITE Turkey + Azerbaijan Rail Organizations Targeting Signature
2023-2024GANANITE European Government Public Water Utilities Oversight Entity Targeting Signature
2023GANANITE Origin, 2023 Dragos Year-in-Review Disclosure

Attribution & Reporting

Attributed by
Dragos (canonical GANANITE Activity Group designation 2023 Year-in-Review)Dragos threat profile / WorldView Threat Intelligence (canonical)CSO Online (canonical Three new advanced threat groups 2024 coverage)Dragos 2025 OT Cybersecurity Year in Review blog (canonical tracking continuation)Dragos threat groups summary 2025 (canonical victim-impersonation tradecraft addition)
Key reporting
reportDragos (2023): canonical GANANITE Activity Group designation 2023 Year-in-Review
reportDragos threat profile / WorldView Threat Intelligence: canonical GANANITE tracking
reportCSO Online (2024): canonical Three new advanced threat groups targeted industrial organizations
reportDragos (2025): canonical 2025 OT Cybersecurity Year in Review continued tracking
reportDragos threat groups summary (2025): canonical victim-impersonation tradecraft addition
reportDragos MITRE ATT&CK for ICS framework: canonical taxonomy listing

Operational

State sponsor

GANANITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report focusing on espionage and data theft targeting critical infrastructure and government entities in the Commonwealth of Independent States (CIS) and Central Asian nations. Per Dragos: "GANANITE targets critical infrastructure and government entities in the Commonwealth of Independent States and Central Asian nations, focusing on espionage and data theft with the possibility of handing off initial access to other threat groups." Honest attribution caveat: Dragos doesn't publicly attribute GANANITE to a specific nation-state consistent with Dragos canonical no-public-nation- attribution policy. Documentation density limited to Dragos public summary disclosures.

Attribution chain: (1) Dragos canonical 2023 Year-in-Review GANANITE disclosure: per Dragos threat profile: "GANANITE targets critical infrastructure and government entities in the Commonwealth of Independent States and Central Asian nations, focusing on espionage and data theft with the possibility of handing off initial access to other threat groups. Although GANANITE has not yet shown evidence of moving into OT networks or an elevated capability resembling Stage 2 actions, their assessed capabilities show efficient use of multiple phases across Stage 1 of the ICS Kill Chain." (2) CSO Online canonical 2024 coverage: per CSO Online covering Dragos 2024 Year-in-Review: "GANANITE has been observed conducting multiple attacks against key personnel related to ICS operations management in a prominent European oil and gas company, rail organizations in Turkey and Azerbaijan, multiple transportation and logistics companies, an automotive machinery company, and at least one European government entity overseeing public water utilities." (3) Dragos 2025 OT Cybersecurity Year in Review GANANITE tracking continuation: per Dragos 2025 blog: "GANANITE: Focused on espionage and data theft targeting Central Asian nations." (4) Dragos threat groups summary 2025 tradecraft addition: per Dragos: "GANANITE: Impersonates victims, exploits vulnerabilities, targets internet-exposed endpoints, and exfiltrates data.

" Operational target profile
  • Commonwealth of Independent States (CIS) signature per Dragos.
  • Central Asian nations signature per Dragos.
  • European oil and gas company signature with ICS operations management key personnel targets.
  • Turkey rail organizations signature per CSO Online.
  • Azerbaijan rail organizations signature per CSO Online (regional geopolitical context Armenia-Azerbaijan conflict consistent with STIBNITE Azerbaijan focus pattern)
  • Transportation + logistics companies multiple per Dragos.
  • Automotive machinery company per Dragos.
  • European government entity overseeing public water utilities per Dragos The cluster fills the Dragos-GANANITE-Activity- Group + CIS-Central-Asia-espionage-targeting + European-oil-and-gas-key-personnel-ICS-operations + Turkey-Azerbaijan-rail-organizations + transportation- logistics-automotive-machinery-multi-sector + European-government-water-utilities-oversight + victim-impersonation-tradecraft + internet- exposed-endpoint-targeting + ICS-Cyber-Kill-Chain- Stage-1-efficient + initial-access-handoff- potential + 2023-Dragos-Year-in-Review-disclosure position in OT/ICS Dragos-newer-taxonomy actor cluster cell.
Motivations
state_actor_dragos_tracked_cis_central_asia_espionage, espionage_data_theft_signature_objective, victim_impersonation_tradecraft_signature, internet_exposed_endpoint_targeting_signature, initial_access_handoff_potential_to_other_threat_groups_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)52/60 · 86%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin