GANANITE
GANANITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report focusing on espionage and data theft targeting critical infrastructure and government entities in the Commonwealth of Independent States (CIS) and Central Asian nations per Dragos canonical threat profile ("GANANITE targets critical infrastructure and government entities in the Commonwealth of Independent States and Central Asian nations, focusing on espionage and data theft with the possibility of handing off initial access to other threat groups") with multi-sector European + Eurasian targeting expansion per CSO Online + Dragos 2024 + 2025 Year-in-Review continued tracking.
state-actor attribution via Dragos canonical 2023 Year-in-Review GANANITE disclosure + 2024 + 2025 Year-in-Review continued tracking + CSO Online canonical Three new advanced threat groups 2024 coverage + Dragos threat groups summary 2025 victim-impersonation tradecraft addition + Dragos MITRE ATT&CK for ICS framework taxonomy listing.
honest attribution caveat Dragos doesn't publicly attribute GANANITE to specific nation-state consistent with canonical no-public-nation-attribution policy.
standalone cluster paralleling laurionite + bauxite + kostovite in v0.1.172 OT/ICS Dragos-newer- taxonomy actor cluster cell continuation extending v0.1.166 chernovite/kamacite/raspite/ covellite classic Dragos taxonomy cell; operational target profile signature CIS + Central Asia geographic focus per Dragos + European oil and gas company ICS operations management key personnel targeting per CSO Online ("GANANITE has been observed conducting multiple attacks against key personnel related to ICS operations management in a prominent European oil and gas company") + Turkey + Azerbaijan rail organizations regional geopolitical context (Armenia-Azerbaijan conflict parallel to STIBNITE Azerbaijan focus) + multiple transportation and logistics companies + automotive machinery company + at least one European government entity overseeing public water utilities.
operational attack architecture: (1) cluster-defining CIS + Central Asia geographic focus distinguishing GANANITE from US-focused ICS clusters like CHERNOVITE + KOSTOVITE + BAUXITE.
(2) cluster-defining European oil and gas ICS operations management key personnel targeting tradecraft with social-engineering focus on individuals managing ICS systems rather than direct ICS network compromise.
(3) cluster- defining Turkey + Azerbaijan rail organizations targeting signature consistent with regional geopolitical context (Armenia-Azerbaijan conflict paralleling STIBNITE 2020 Azerbaijan wind turbine targeting pattern)
(4) cluster-defining multi- sector targeting with transportation + logistics + automotive machinery + European government water utilities oversight reflecting broad critical- infrastructure intelligence collection objectives; (5) cluster-defining victim impersonation tradecraft per Dragos 2025 threat groups summary ("GANANITE: Impersonates victims, exploits vulnerabilities, targets internet-exposed endpoints, and exfiltrates data") establishing social-engineering + identity-spoofing as operational signature.
(6) cluster-defining internet-exposed endpoint exploitation tradecraft per Dragos 2025 with vulnerability exploitation against publicly-accessible assets.
(7) cluster- defining initial access handoff potential signature paralleling KAMACITE access-enablement- team operational model per Dragos ("focusing on espionage and data theft with the possibility of handing off initial access to other threat groups... Industrial organizations in Europe and Central Asia face a significant risk from GANANITE due to their initial intrusion capabilities, post- compromise espionage TTPs, and intellectual property theft, all of which can be used in follow-on attacks against the victim organizations"); (8) cluster-defining ICS Cyber Kill Chain Stage 1 efficient multi-phase utilization per Dragos ("their assessed capabilities show efficient use of multiple phases across Stage 1 of the ICS Kill Chain") with no OT-network movement observed consistent with Stage 1 focus.
(9) signature intellectual property theft objective expansion from base espionage + data theft per Dragos; (10) signature Dragos 2025 OT Cybersecurity Year in Review continued tracking establishing operational continuity + active-tracking-status; (11) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference- status alongside other Dragos-tracked clusters; cluster fills the Dragos-GANANITE-Activity-Group + CIS-Central-Asia-espionage-targeting + European- oil-and-gas-key-personnel-ICS-operations + Turkey- Azerbaijan-rail-organizations + transportation- logistics-automotive-machinery-multi-sector + European-government-water-utilities-oversight + victim-impersonation-tradecraft + internet- exposed-endpoint-targeting + ICS-Cyber-Kill-Chain- Stage-1-efficient + initial-access-handoff- potential + 2023-Dragos-Year-in-Review-disclosure position in OT/ICS Dragos-newer-taxonomy actor cluster cell.
canonical illustration of CIS + Central Asia espionage-focused ICS Activity Group + European oil and gas key-personnel targeting + Turkey/Azerbaijan rail + multi-sector transportation + automotive + water utilities targeting + victim impersonation tradecraft + initial-access-handoff KAMACITE-parallel operational pattern cited in essentially all subsequent Dragos-taxonomy newer- cluster industry analyses through 2023-2026 period.