KAMACITE
KAMACITE is Dragos's tracked Activity Group designation for a long-running ICS-targeting threat group active since at least 2014 that operates as an "access-enablement team" enabling other entities, specifically ELECTRUM (Sandworm) , to deliver ICS-specific attacks, while not directly causing ICS disruptive events itself per Dragos canonical framing ("KAMACITE typically transfers operational control to other entities such as ELECTRUM in the 2016 Ukraine event, and some unknown entity in the 2015 Ukraine event, to execute ICS disruptive effects while maintaining access")
Russia-aligned attribution via Dragos canonical KAMACITE Activity Group designation + ELECTRUM-access-enablement-team framing + SecurityWeek canonical Four Additional Threat Groups Targeting Industrial Organizations 2020 coverage + CSO Online canonical Three new advanced threat groups 2024 coverage + Enterprise Times canonical Dragos 2024 lowered the barrier for OT/ICS attacks 2025 coverage + Dragos blog "New ICS Threat Activity Group KAMACITE" canonical access-enablement-team framing.
honest attribution caveat: KAMACITE operationally interleaves with Sandworm/ELECTRUM (already curated as sandworm_team) to the point that the Dragos-distinct-tracking-from-Sandworm methodology is best understood as a tradecraft-and-toolset cluster within broader Russia-aligned ICS operations rather than a fully separate APT, curated as standalone cluster to preserve Dragos- taxonomy disciplined-distinction methodology for analysts referencing Dragos terminology.
standalone cluster paralleling chernovite_pipedream + raspite_leafminer + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.
operational target profile signature electric utilities + oil and gas operations + manufacturing longstanding per Dragos + US energy sector targeting per SecurityWeek 2020 + Ukrainian critical infrastructure via ELECTRUM-enablement 2015 + 2016 + post-2022 operations + European Oil & Natural Gas 2024 targeting expansion per Enterprise Times Dragos 2025 report.
operational attack architecture: (1) cluster-defining access-enablement-team operational model per Dragos distinguishing KAMACITE from disruption- execution actors with operational hand-off pattern transferring control to ELECTRUM for ICS disruptive effects.
(2) cluster-defining 2014 operational origin establishing 6+ year tradecraft consistency per Dragos ("While the group has evolved over time, many aspects of its operations and tradecraft have remained remarkably similar over the past six years")
(3) cluster- defining BLACKENERGY2 + BLACKENERGY3 + GREYENERGY custom malware framework delivery with historical phishing activity associated with delivery or follow-on download per Dragos canonical tradecraft signature.
(4) cluster-defining 2015 + 2016 Ukraine power event facilitation signature with 2016 Ukraine event canonical ELECTRUM hand-off pattern establishing distinct-but-interleaved operational model.
(5) cluster-defining compromised-third-party-server + Tor-nodes-relays + Virtual-Private-Server criminal-operations C2 infrastructure tradecraft per Dragos ("KAMACITE almost exclusively leverages compromised third- party servers for network infrastructure. Network infrastructure and communication frequently only reference server Internet Protocol IP addresses with rare use of domains... This includes Tor nodes and relays, and Virtual Private Server VPS instances associated with criminal operations"); (6) signature spearphishing with malicious attachments + external access via legitimate services replaying captured credentials initial access + Ukrainian political/financial themes + technical conference content phishing lures per Dragos canonical tradecraft.
(7) signature Mimikatz credential capture + PSExec lateral movement via built-in system tools + common administration frameworks per Dragos canonical tradecraft chain.
(8) signature 2024 European Oil & Natural Gas operational expansion per Enterprise Times 2025 Dragos report.
(9) signature 2025 SOHO router exploitation tradecraft evolution per Dragos threat groups summary 2025.
(10) signature IP-address-only C2 with rare use of domains operational distinctive pattern.
(11) signature US energy sector operational expansion 2020 per SecurityWeek; cluster fills the Dragos-KAMACITE-Activity-Group + Sandworm-ELECTRUM-distinct-but-interleaved- access-enablement-team + 2014-active-since + BLACKENERGY2-campaign-facilitation + 2015-2016- Ukraine-power-event-facilitation + BLACKENERGY2- BLACKENERGY3-GREYENERGY-malware-delivery + compromised-third-party-server-Tor-VPS-C2- infrastructure + phishing-Ukrainian-political- financial-technical-conference-lures + Mimikatz- credential-capture-PSExec-lateral-movement + European-Oil-Natural-Gas-2024-targeting + 2025- SOHO-router-exploitation position in OT/ICS Dragos-taxonomy actor cluster cell.
canonical illustration of access-enablement-team operational model + Dragos-taxonomy distinct-tracking-from- Sandworm methodology + long-running 2014+ operational tradecraft consistency + ELECTRUM operational handoff pattern + BLACKENERGY2/3/ GREYENERGY malware framework delivery + compromised- third-party-server + Tor + VPS C2 infrastructure distinctive tradecraft cited in essentially all subsequent Russia-aligned ICS-targeting industry analyses through 2014-2026 period.