Home/Threat Actor/LAURIONITE
Threat Actor

LAURIONITE

laurionite · state_actor_dragos_tracked_oracle_isupplier_specialist_2023_disclosed · active since 2023-01

LAURIONITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report specializing in Oracle E-Business Suite iSupplier web services exploitation across aviation + automotive + manufacturing + government industrial sectors using open-source offensive security tooling + public proof-of-concept tradecraft per Dragos canonical threat profile ("LAURIONITE is a threat group that uses open-source offensive security tooling with public proof of concepts to aid in exploiting common vulnerabilities, targeting industrial organizations including manufacturing. LAURIONITE was first discovered actively targeting and exploiting Oracle E-Business Suite iSupplier web services and assets across several industries, including aviation, automotive, manufacturing, and government")

state-actor attribution via Dragos canonical 2023 Year-in-Review LAURIONITE disclosure + 2024 + 2025 Year-in-Review continued tracking + CSO Online canonical Three new advanced threat groups 2024 coverage + Dragos MITRE ATT&CK for ICS framework taxonomy listing.

honest attribution caveat Dragos doesn't publicly attribute LAURIONITE to specific nation-state consistent with canonical no-public-nation- attribution policy + documentation density limited to Dragos public summary disclosures with full technical details available only via Dragos WorldView Threat Intelligence subscription; standalone cluster paralleling gananite + bauxite + kostovite in v0.1.172 OT/ICS Dragos-newer- taxonomy actor cluster cell continuation extending v0.1.166 chernovite/kamacite/raspite/covellite classic Dragos taxonomy cell.

operational target profile signature aviation + automotive + manufacturing + government multi-industrial sector targeting per Dragos with Oracle E-Business Suite iSupplier instance operators across organizations using Oracle enterprise solutions for integrated business processes + supply chain + vendor relationship intelligence target potential per Dragos no-yet-observed OT-pivot assessment; operational attack architecture: (1) cluster- defining Oracle E-Business Suite iSupplier web services exploitation specialization with iSupplier instance vulnerabilities targeting providing access to supplier + vendor relationship intelligence.

(2) cluster-defining open-source offensive security tooling tradecraft with public proof-of-concept exploit usage rather than custom malware development.

(3) cluster-defining aviation + automotive + manufacturing + government multi-industrial sector targeting signature per Dragos + CSO Online coverage.

(4) cluster- defining ICS Cyber Kill Chain Stage 1 complete attack cycle capability per Dragos canonical assessment ("LAURIONITE has demonstrated the ability to conduct the complete attack cycle of offensive cyber operations that achieve Stage 1 of the ICS Cyber Kill Chain") establishing full- Stage-1 reconnaissance + initial access + collection + exfiltration capability without demonstrated Stage 2 disruptive operations.

(5) cluster- defining compromised infrastructure C2 obfuscation tradecraft with trusted-organization origin masking for detection evasion per Dragos ("By utilizing compromised infrastructure, LAURIONITE can remain undetected or overlooked due to its origin being from trusted or known organizations"); (6) signature supply chain vendor relationship intelligence theft potential per Dragos no-yet- observed OT-pivot assessment ("LAURIONITE has not been observed attempting to pivot to OT networks yet, but the potential is there given its targets and the type of information about suppliers and vendor relationships that Oracle E-Business Suite iSupplier instances might contain")

(7) signature Dragos 2025 OT Cybersecurity Year in Review continued tracking establishing operational continuity + active-tracking-status.

(8) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference-status alongside BAUXITE + BENTONITE + CHERNOVITE + CHRYSENE + DYMALLOY + ELECTRUM + GANANITE + GRAPHITE + HEXANE + KAMACITE + KOSTOVITE + MAGNALLIUM + PARISITE + PETROVITE + RASPITE + STIBNITE + TALONITE + VANADINITE + VOLTZITE + WASSONITE + XENOTIME Dragos-tracked clusters; cluster fills the Dragos-LAURIONITE-Activity- Group + Oracle-E-Business-Suite-iSupplier-web- services-exploitation-specialist + open-source- offensive-tooling-public-PoC-tradecraft + aviation- automotive-manufacturing-government-multi-industrial + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus + compromised-infrastructure-C2-obfuscation + supply-chain-vendor-relationship-intelligence- theft-potential + 2023-Dragos-Year-in-Review- disclosure position in OT/ICS Dragos-newer- taxonomy actor cluster cell.

canonical illustration of Oracle E-Business Suite iSupplier exploitation specialist + open-source-offensive-tooling + public-PoC-based tradecraft + multi-industrial- sector targeting + ICS Cyber Kill Chain Stage 1 complete-attack-cycle capability + compromised- infrastructure trusted-origin masking detection evasion cited in essentially all subsequent Dragos-taxonomy newer-cluster industry analyses through 2023-2026 period.

state_actor_dragos_tracked_oracle_isupplier_specialist_2023_disclosed confidence: high 14 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

LAURIONITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report specializing in Oracle E-Business Suite iSupplier web services exploitation across aviation + automotive + manufacturing + government industrial sectors using open-source offensive security tooling + public proof-of-concept tradecraft. State-actor attribution via Dragos canonical 2023 Year-in-Review LAURIONITE disclosure + 2024 + 2025 Year-in-Review continued tracking + CSO Online industry coverage. Honest attribution caveat: Dragos doesn't publicly attribute to specific nations consistent with canonical policy.

Standalone cluster paralleling gananite + bauxite + kostovite in v0.1.172 OT/ICS Dragos-newer- taxonomy actor cluster cell continuation (extending v0.1.166 chernovite/kamacite/raspite/ covellite classic Dragos taxonomy cell).

Operational target profile
  • Aviation industry signature.
  • Automotive industry signature.
  • Manufacturing industry signature.
  • Government sector signature.
  • Oracle E-Business Suite iSupplier instance operators signature.
  • No demonstrated OT-pivot per Dragos despite potential Operational attack architecture: (1) Oracle E-Business Suite iSupplier web services exploitation specialization (cluster- defining) (2) Open-source offensive security tooling + public PoC tradecraft (cluster-defining) (3) Aviation + automotive + manufacturing + government multi-industrial targeting (cluster- defining) (4) ICS Cyber Kill Chain Stage 1 complete attack cycle capability (cluster-defining) (5) Compromised infrastructure trusted-origin masking C2 obfuscation (cluster-defining) (6) Supply chain vendor relationship intelligence theft potential (signature) The cluster fills the Dragos-LAURIONITE-Activity- Group + Oracle-E-Business-Suite-iSupplier-web- services-exploitation-specialist + open-source- offensive-tooling-public-PoC-tradecraft + aviation- automotive-manufacturing-government-multi-industrial + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus + compromised-infrastructure-C2-obfuscation + supply-chain-vendor-relationship-intelligence- theft-potential + 2023-Dragos-Year-in-Review- disclosure position in OT/ICS Dragos-newer- taxonomy actor cluster cell.

Aliases

14
laurionitelaurionite activity groupdragos laurionite trackinglaurionite oracle e-business suite isupplier exploitationlaurionite open source offensive security tooling tradecraftlaurionite public proof of concept poc exploitation tradecraftlaurionite aviation automotive manufacturing government industrial targetinglaurionite 2023 dragos year-in-review disclosurelaurionite ics cyber kill chain stage 1 capabilitylaurionite compromised infrastructure c2 obfuscation tradecraftlaurionite supply chain vendor relationship intelligence theftlaurionite multi-industrial sector targetinglaurionite enterprise solution exploitation specialistlaurionite trusted organization infrastructure compromise signature

Notable Campaigns

8
2025LAURIONITE 2025 Dragos Continued Tracking Signature
2023-2026Continued Industry Reference Status (2023-2026)
2023-2025LAURIONITE Open-Source Offensive Tooling + Public PoC Tradecraft Signature
2023-2025LAURIONITE Compromised Infrastructure Trusted-Origin Masking Signature
2023-2025LAURIONITE ICS Cyber Kill Chain Stage 1 Complete Attack Cycle Signature
2023-2025LAURIONITE Supply Chain Vendor Intelligence Theft Potential Assessment Signature
2023-2024LAURIONITE Aviation + Automotive + Manufacturing + Government Multi-Industrial Targeting Signature
2023LAURIONITE Origin, 2023 Oracle E-Business Suite iSupplier First Discovery

Attribution & Reporting

Attributed by
Dragos (canonical LAURIONITE Activity Group designation 2023 Year-in-Review)Dragos threat profile / WorldView Threat Intelligence (canonical)CSO Online (canonical Three new advanced threat groups 2024 coverage)Dragos 2025 OT Cybersecurity Year in Review blog (canonical tracking continuation)Dragos MITRE ATT&CK for ICS framework documentation (canonical taxonomy listing)
Key reporting
reportDragos (2023): canonical LAURIONITE Activity Group designation 2023 Year-in-Review
reportDragos threat profile / WorldView Threat Intelligence: canonical LAURIONITE tracking
reportCSO Online (2024): canonical Three new advanced threat groups targeted industrial organizations
reportDragos (2025): canonical 2025 OT Cybersecurity Year in Review continued tracking
reportDragos MITRE ATT&CK for ICS framework: canonical taxonomy listing

Operational

State sponsor

LAURIONITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group disclosed in Dragos 2023 Year-in-Review report specializing in Oracle E-Business Suite iSupplier web services exploitation. Per Dragos: "LAURIONITE is a threat group that uses open-source offensive security tooling with public proof of concepts to aid in exploiting common vulnerabilities, targeting industrial organizations including manufacturing. LAURIONITE was first discovered actively targeting and exploiting Oracle E-Business Suite iSupplier web services and assets across several industries, including aviation, automotive, manufacturing, and government." Honest attribution caveat: Dragos doesn't publicly attribute LAURIONITE to a specific nation-state consistent with Dragos canonical no-public-nation- attribution policy.

Documentation density limited to Dragos public summary disclosures with full technical details available only via Dragos WorldView Threat Intelligence subscription. Attribution chain: (1) Dragos canonical 2023 Year-in-Review LAURIONITE disclosure: per Dragos threat profile: "LAURIONITE has demonstrated the ability to conduct the complete attack cycle of offensive cyber operations that achieve Stage 1 of the ICS Cyber Kill Chain. By utilizing compromised infrastructure, LAURIONITE can remain undetected or overlooked due to its origin being from trusted or known organizations." (2) CSO Online canonical 2024 coverage: per CSO Online covering Dragos 2024 Year-in-Review: "The third new group, LAURIONITE, has been observed exploiting vulnerabilities in Oracle E-Business Suite iSupplier web services belonging to organizations from the aviation, automotive, manufacturing, and government sectors.

Oracle E-Business Suite is a popular enterprise solution for integrated business processes used across many industries. LAURIONITE has not been observed attempting to pivot to OT networks yet, but the potential is there given its targets and the type of information about suppliers and vendor relationships that Oracle E-Business Suite iSupplier instances might contain." (3) Dragos 2025 OT Cybersecurity Year in Review LAURIONITE tracking continuation: per Dragos 2025 blog: "LAURIONITE: Exploits Oracle E-Business Suite to infiltrate industries such as aviation, manufacturing, and government.

" Operational target profile
  • Aviation industry signature per Dragos.
  • Automotive industry signature per Dragos.
  • Manufacturing industry signature per Dragos.
  • Government sector signature per Dragos.
  • Oracle E-Business Suite iSupplier instance operators signature target population.
  • Supply chain + vendor relationship intelligence targets per Dragos potential-pivot assessment.
  • No demonstrated OT-network pivot per Dragos despite potential given targets The cluster fills the Dragos-LAURIONITE-Activity- Group + Oracle-E-Business-Suite-iSupplier-web- services-exploitation-specialist + open-source- offensive-tooling-public-PoC-tradecraft + aviation- automotive-manufacturing-government-multi-industrial + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus + compromised-infrastructure-C2-obfuscation + supply-chain-vendor-relationship-intelligence- theft-potential + 2023-Dragos-Year-in-Review- disclosure position in OT/ICS Dragos-newer- taxonomy actor cluster cell.
Motivations
state_actor_dragos_tracked_oracle_isupplier_specialist, oracle_e_business_suite_isupplier_web_services_exploitation_signature, open_source_offensive_tooling_public_poc_tradecraft_signature, aviation_automotive_manufacturing_government_multi_industrial_targeting, supply_chain_vendor_relationship_intelligence_theft_potential
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)52/60 · 86%
Analytics (MITRE CAR)27/60 · 45%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MANUFACTURING INDUSTRIAL SECTOR TARGETINGSUPPLY CHAIN VENDOR RELATIONSHIP INTELLIGENCE THEFT POTENTIAL
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin