Dragonfly is a Russia-linked cyber espionage threat cluster associated with the Russian Federal Security Service (FSB), commonly tied to FSB Center 16. It is widely tracked under multiple overlapping aliases including Berserk Bear, Energetic Bear, Crouching Yeti, Ghost Blizzard, Static Tundra, Blue Kraken, Bromine, Dymalloy, Iron Liberty, Koala Team, Temp.Isotope, and TG-4192. Public reporting indicates that some of these names may refer to closely related or partially overlapping activity clusters rather than a perfectly uniform single actor, but Dragonfly is consistently used for Russian state-sponsored activity focused on long-term access, intelligence collection, and compromise of network infrastructure. Dragonfly has been active for more than a decade and is known for persistent intrusions that can remain undetected for extended periods while collecting operational and network intelligence. The actor has repeatedly targeted critical infrastructure and other strategically relevant sectors, including energy, communications, telecommunications, defense, finance, government, healthcare, higher education, manufacturing, and the defense industrial base. Victimology has prominently included Ukraine and allied countries, with additional activity observed globally, including in Africa. A defining characteristic of Dragonfly activity is the targeting of routers and other edge networking devices as an initial access and persistence layer. The actor has been observed scanning internet-facing address space for devices exposing SNMP services with default, weak, or common community strings, then abusing SNMP set functionality to force devices to export configuration data. Those stolen configurations can reveal credentials, topology, and management details that enable deeper intrusion into enterprise and operational technology environments. Dragonfly has also exploited weaknesses in Cisco network infrastructure, including Cisco Smart Install and known vulnerabilities such as CVE-2018-0171 and CVE-2008-4128, and has abused web-based management portals on network devices. These operations are frequently described as opportunistic at scale, but they support strategic access into critical infrastructure networks. The group’s tradecraft aligns with espionage and pre-positioning objectives. Reported behavior includes long-term reconnaissance, theft of device configurations, credential harvesting opportunities derived from network infrastructure compromise, and follow-on access into sensitive environments, including networks with industrial control system relevance. Dragonfly has also been associated with Windows host activity such as Registry querying for victim profiling, Registry modification, and Registry Run-key persistence. ATT&CK-aligned behaviors reflected in reporting include use of Valid Accounts, Exploit Public-Facing Application, Network Device Discovery, Gather Victim Network Information, Registry Query, Modify Registry, and Boot or Logon Autostart Execution. Dragonfly is part of a broader set of Russian intelligence-linked cyber operations that emphasize stealthy access, infrastructure compromise, and intelligence collection against critical systems. In some reporting, Dragonfly is discussed alongside or within the same operational ecosystem as Berserk Bear, Energetic Bear, Ghost Blizzard, and Static Tundra, all linked to FSB Center 16 activity. Security professionals should therefore treat Dragonfly as a label for a mature Russian state-sponsored intrusion set centered on network-device exploitation, critical-infrastructure targeting, and durable espionage access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
They have also exploited CVE-2018-0171 and CVE-2008-4128 in Cisco devices, both now listed in CISA’s Known Exploited Vulnerabilities catalog.
They have also exploited CVE-2018-0171 and CVE-2008-4128 in Cisco devices, both now listed in CISA’s Known Exploited Vulnerabilities catalog.
Dragonfly has conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.
The APT actor scanned for vulnerable Citrix and Microsoft Exchange services and identified vulnerable systems, likely for future exploitation. This actor continues to exploit a Citrix Directory Traversal Bug (CVE-2019-19781) and a Microsoft Exchange remote code execution flaw (CVE-2020-0688).
They also used compromised of Microsoft Office 365 (O365) accounts and attempted to exploit the ZeroLogon Windows Netlogon vulnerability (CVE-2020-1472) for privilege escalation on Windows Active Directory (AD) servers.
19 more CVEs tied to this actor tracked in Mallory.
57 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state-sponsored actors exploiting poorly configured and vulnerable networking devices, scanning for devices accepting default SNMP community strings, exfiltrating device configurations over TFTP, and exploiting Cisco vulnerabilities to gain deeper access.
Russian FSB Center 16-linked actors are scanning for poorly secured network devices, especially routers, exploiting weak/default SNMP credentials, stealing device configurations via spoofed requests, transferring them to attacker-controlled servers over TFTP/FTP, and occasionally exploiting Cisco vulnerabilities and management interfaces to access critical infrastructure networks.
Russian government-backed cyber actors linked to the FSB have spent years targeting vulnerable or poorly configured internet routers used by businesses and critical infrastructure to gain access to sensitive networks.
Russian state-sponsored activity targeting poorly secured networking devices, mainly routers, across global critical infrastructure networks by abusing SNMP configuration transfer behavior and exploiting known Cisco vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.