TALONITE
TALONITE is a threat activity group tracked by Dragos since July 2019. Its operations have focused on initial access compromises in the U.S. electric sector. Reported victimology also includes electric utilities in Japan and Taiwan, and its infrastructure is described as almost exclusively based in East Asia. TALONITE primarily uses spearphishing with malicious documents or executables for initial access, including engineering-themed lures designed to exploit trust. The group uses two custom multi-component malware families, LookBack and FlowCloud, and also abuses legitimate binaries or modifies legitimate binaries to add malicious functionality. Dragos describes TALONITE as blending tactics and using a mix of adversary-owned and compromised infrastructure, making the activity difficult to track and contain. The described ICS impact includes initial access, information gathering, and enabling further operations within the electric sector. Dragos reported behavioral overlap with the China-linked APT10 group, but stated it could not definitively attribute TALONITE to APT10. No additional aliases or sub-groups were provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- energy
Associated malware families
2 malware families attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses spearphishing with malicious documents or executables to gain initial access.
Initial-access focused intrusion activity against electric utilities using spearphishing with malicious documents/executables, followed by custom malware deployment and information gathering to enable further operations in the electric sector.
Uses spearphishing with malicious documents or executables to gain initial access.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.