NoisyBear is a newly identified threat actor associated with Operation BarrelFire, a campaign reported in 2025 as targeting Kazakhstan’s energy sector, particularly KazMunayGas. The actor has been described as likely Russian-linked based on reported use of Russian language, infrastructure associated with the Russia-based hosting provider Aeza Group, and claimed similarities to prior Moscow-linked activity. The attribution remains tentative rather than definitive. Reported activity attributed to NoisyBear centered on phishing operations using a compromised internal finance mailbox to send messages themed as corporate policy updates, salary changes, and IT notices. The delivery chain reportedly used malicious archive attachments and a multi-stage infection sequence involving shortcut files, batch scripts, PowerShell-based loaders, and a DLL implant capable of executing shellcode and enabling reverse-shell style access. These tradecraft elements indicate an intrusion set focused on initial access, execution, persistence, defense evasion, and post-compromise control. The actor’s observed targeting is concentrated on Central Asia’s energy sector, with Kazakhstan identified as the principal victim geography in public reporting. Available reporting does not establish ransomware or extortion activity by NoisyBear. Public claims around the KazMunayGas incident were disputed by the victim organization, which stated the activity was part of an internal phishing-awareness exercise; accordingly, operational details should be treated with caution where independently uncorroborated. Known naming variants include Noisy Bear and noisy_bear.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-origin-suspected cluster tied to Operation BarrelFire targeting Kazakhstan energy sector; later described as a planned phishing test.
Alleged (and disputed) cyber-espionage/phishing activity targeting Kazakhstan's oil and gas sector; the named victim (KazMunayGas) claims the observed activity/screenshots were from an internal phishing training exercise rather than a real intrusion.
Conducting phishing campaigns targeting Central Asia's energy sector, delivering malware via malicious email attachments.
Conducting phishing campaigns targeting Central Asia's energy sector, delivering malware via malicious email attachments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.