Dragonfly is a Russian state-linked cyber-espionage threat actor active since at least 2010, best known for targeting industrial control system environments and critical infrastructure. It is also tracked as Energetic Bear, Berserk Bear, Crouching Yeti, Dymalloy, TEMP.Isotope, Ghost Blizzard, Static Tundra, Blue Kraken, Bromine, Iron Liberty, Koala Team, TG-4192, and Dragonfly 2.0. Its operations have targeted energy, utilities, nuclear, water, aviation, government, critical-manufacturing, and industrial-control organizations, as well as suppliers supporting those sectors. Dragonfly has used spearphishing attachments, watering-hole compromises, credential-harvesting lures, compromise of trusted third parties, and trojanized industrial software to obtain access. In supply-chain operations, it compromised software providers supporting programmable logic controller access, specialist industrial devices, and energy-infrastructure management. The group has deployed Havex (also known as Backdoor.Oldrea or Energetic Bear RAT) and modified Karagany malware to collect host, network, VPN, contact, document, password, and screenshot data. The group conducts extensive reconnaissance of enterprise and operational-technology environments, including file servers and ICS/SCADA-related materials. It has used stolen or harvested credentials, remote-access services, web shells, scheduled tasks, PowerShell, Windows Registry modification, created accounts, and remote administration tooling to maintain access, pivot through supplier networks, and support post-compromise activity. Operators have also deleted operational artifacts to impede investigation. Dragonfly-linked infrastructure was attributed to a destructive campaign against Polish energy facilities in late 2025. That operation involved long-term reconnaissance of industrial and OT networks, theft of directory, remote-access configuration, and modernization information, followed by deployment of DYNOWIPER, a Windows data-wiping malware family designed to corrupt files across local and removable storage while preserving core operating-system components.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The alert directly connects them to reports of the Russian Federal Security Service's (FSB) Center 16 - aka Berserk Bear - accused of using a flaw (CVE-2018-0171) Cisco patched in 2018... The Cisco issue is with the Smart Install feature of Cisco IOS and IOS XE software, a CVSS 9.8 flaw, and one that many end-of-life-kit can't patch.
Exploit Public-Facing Application T1190 Conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.
Exploit Public-Facing Application T1190 Conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.
ALLANITE and DYMALLOY continued to target multiple United States (U.S.) industrial entities from September through October 2020. Operations included use of ZeroLogon to further intrusions into victim networks.
They have also exploited CVE-2018-0171 and CVE-2008-4128 in Cisco devices, both now listed in CISA’s Known Exploited Vulnerabilities catalog.
19 more CVEs tied to this actor tracked in Mallory.
118 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection's Annotations section.
Mentioned only as an annotation associated with a detection for PYTHONPATH modification during package installation; no specific Dragonfly activity is described.
Dragonfly is listed only in the detection's annotations.
Dragonfly is listed in the detection's annotations for Python site-hook creation during package installation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.