LAURIONITE
LAURIONITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report specializing in Oracle E-Business Suite iSupplier web services exploitation across aviation + automotive + manufacturing + government industrial sectors using open-source offensive security tooling + public proof-of-concept tradecraft per Dragos canonical threat profile ("LAURIONITE is a threat group that uses open-source offensive security tooling with public proof of concepts to aid in exploiting common vulnerabilities, targeting industrial organizations including manufacturing. LAURIONITE was first discovered actively targeting and exploiting Oracle E-Business Suite iSupplier web services and assets across several industries, including aviation, automotive, manufacturing, and government")
state-actor attribution via Dragos canonical 2023 Year-in-Review LAURIONITE disclosure + 2024 + 2025 Year-in-Review continued tracking + CSO Online canonical Three new advanced threat groups 2024 coverage + Dragos MITRE ATT&CK for ICS framework taxonomy listing.
honest attribution caveat Dragos doesn't publicly attribute LAURIONITE to specific nation-state consistent with canonical no-public-nation- attribution policy + documentation density limited to Dragos public summary disclosures with full technical details available only via Dragos WorldView Threat Intelligence subscription; standalone cluster paralleling gananite + bauxite + kostovite in v0.1.172 OT/ICS Dragos-newer- taxonomy actor cluster cell continuation extending v0.1.166 chernovite/kamacite/raspite/covellite classic Dragos taxonomy cell.
operational target profile signature aviation + automotive + manufacturing + government multi-industrial sector targeting per Dragos with Oracle E-Business Suite iSupplier instance operators across organizations using Oracle enterprise solutions for integrated business processes + supply chain + vendor relationship intelligence target potential per Dragos no-yet-observed OT-pivot assessment; operational attack architecture: (1) cluster- defining Oracle E-Business Suite iSupplier web services exploitation specialization with iSupplier instance vulnerabilities targeting providing access to supplier + vendor relationship intelligence.
(2) cluster-defining open-source offensive security tooling tradecraft with public proof-of-concept exploit usage rather than custom malware development.
(3) cluster-defining aviation + automotive + manufacturing + government multi-industrial sector targeting signature per Dragos + CSO Online coverage.
(4) cluster- defining ICS Cyber Kill Chain Stage 1 complete attack cycle capability per Dragos canonical assessment ("LAURIONITE has demonstrated the ability to conduct the complete attack cycle of offensive cyber operations that achieve Stage 1 of the ICS Cyber Kill Chain") establishing full- Stage-1 reconnaissance + initial access + collection + exfiltration capability without demonstrated Stage 2 disruptive operations.
(5) cluster- defining compromised infrastructure C2 obfuscation tradecraft with trusted-organization origin masking for detection evasion per Dragos ("By utilizing compromised infrastructure, LAURIONITE can remain undetected or overlooked due to its origin being from trusted or known organizations"); (6) signature supply chain vendor relationship intelligence theft potential per Dragos no-yet- observed OT-pivot assessment ("LAURIONITE has not been observed attempting to pivot to OT networks yet, but the potential is there given its targets and the type of information about suppliers and vendor relationships that Oracle E-Business Suite iSupplier instances might contain")
(7) signature Dragos 2025 OT Cybersecurity Year in Review continued tracking establishing operational continuity + active-tracking-status.
(8) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference-status alongside BAUXITE + BENTONITE + CHERNOVITE + CHRYSENE + DYMALLOY + ELECTRUM + GANANITE + GRAPHITE + HEXANE + KAMACITE + KOSTOVITE + MAGNALLIUM + PARISITE + PETROVITE + RASPITE + STIBNITE + TALONITE + VANADINITE + VOLTZITE + WASSONITE + XENOTIME Dragos-tracked clusters; cluster fills the Dragos-LAURIONITE-Activity- Group + Oracle-E-Business-Suite-iSupplier-web- services-exploitation-specialist + open-source- offensive-tooling-public-PoC-tradecraft + aviation- automotive-manufacturing-government-multi-industrial + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus + compromised-infrastructure-C2-obfuscation + supply-chain-vendor-relationship-intelligence- theft-potential + 2023-Dragos-Year-in-Review- disclosure position in OT/ICS Dragos-newer- taxonomy actor cluster cell.
canonical illustration of Oracle E-Business Suite iSupplier exploitation specialist + open-source-offensive-tooling + public-PoC-based tradecraft + multi-industrial- sector targeting + ICS Cyber Kill Chain Stage 1 complete-attack-cycle capability + compromised- infrastructure trusted-origin masking detection evasion cited in essentially all subsequent Dragos-taxonomy newer-cluster industry analyses through 2023-2026 period.