STIBNITE is a Dragos-tracked industrial threat activity group focused on Azerbaijani targets, particularly wind generation organizations and government entities. The group was observed conducting multiple intrusion operations from late 2019 through 2020 and is assessed to have operated primarily at Stage 1 of the ICS Cyber Kill Chain, emphasizing initial access, credential theft, and information gathering rather than confirmed disruptive effects in operational technology environments. Its targeting indicates explicit interest in industrial control system access associated with wind power operations in Azerbaijan. STIBNITE used credential theft websites spoofing Azerbaijani government organizations and spearphishing campaigns with malicious Microsoft Office documents to gain access. Post-compromise activity included deployment of the custom PoetRAT malware for collection and command execution, including file listing, screenshot capture, file transfer, and remote command execution. The group also used credential-harvesting tooling including PypyKatz and LaZagne, along with additional browser credential theft resources. Command-and-control activity relied on dynamic DNS-backed infrastructure and common network ports, and infrastructure reuse was observed across 2020 campaigns. Data encoding and decoding routines based on an Affine substitution cipher were also reported. Observed activity was concentrated in IT networks, but the credentials and network information collected by STIBNITE could support propagation through victim environments and enable later compromise of ICS networks. The group is therefore notable as an industrially focused intrusion set with demonstrated reconnaissance and access-development behavior against renewable energy infrastructure in the Caucasus. No confirmed ransomware or extortion activity is associated with STIBNITE in the available reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS/OT-focused intrusion activity targeting wind generation and government entities in Azerbaijan, conducting Stage 1 ICS Cyber Kill Chain operations centered on initial access, credential theft, and information gathering to enable potential follow-on ICS compromise.
STIBNITE is known for targeting wind generation organizations and government entities in Azerbaijan using spearphishing campaigns to deliver custom malware (PoetRAT).
Compromises IT networks through insecure VPNs for reconnaissance.
Compromises IT networks through insecure VPNs for reconnaissance.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.