Karagany, also referred to as Trojan.Karagany and Xfrost, is a backdoor/RAT associated in the provided content with Russia-linked activity, particularly the IRON LIBERTY threat group, also known as Energetic Bear and Dragonfly. The malware has been used in campaigns targeting energy and ICS-related organizations, including watering hole operations on energy sector websites and infections delivered alongside or via Havex/Oldrea. Secureworks reported a version of Karagany that it assessed was exclusively used by IRON LIBERTY.
Documented capabilities include gathering information about the user on a compromised host; stealing data and credentials from browsers; capturing keystrokes; monitoring titles of open windows to identify specific keywords; taking desktop screenshots; creating directories to store plugin output and stage data for exfiltration; transferring files to and from Dragonfly command-and-control servers; and securing C2 communications with SSL/TLS. One cited screenshot artifact is saved as \ProgramData\Mail\MailAg\shot.png.
The content also notes that Karagany samples sometimes use common binary packers such as UPX and Aspack in addition to a custom Delphi binary packer.
In one Secureworks incident response case, forensic evidence indicated Karagany was delivered through a trojanized Adobe Flash installer in a likely man-on-the-side attack. In that case, a file identified as Karagany (set170.exe) was created in %APPDATA%, then copied as SearchIndexer.exe into %APPDATA%\Local\SearchIndexer, with persistence established via a shortcut in the user’s Startup folder. Secureworks also observed timestomping indicators on SearchIndexer.exe. The same reporting states IRON LIBERTY has historically targeted global energy, nuclear, and defense organizations.
The content further places Karagany among commodity malware families used by Dragonfly/DYMALLOY, alongside Goodor and DorShel, and notes it may be deployed as an additional payload during broader intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The chaining or combination of multiple legacy vulnerability exploits with exploitation of the newer Windows Zerologon vulnerability | This group avoids using custom malware, opting for commodity malware families that hinder attempts at applying attribution... • Use of commodity malware such as Goodor, DorShel, and Karagany
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During this particular engagement, the Secureworks Advanced Endpoint Threat Detection (AETD) - Red Cloak™ solution detected that a system was compromised with the Karagany malware. This version of Karagany is exclusively used by the Russia-based IRON LIBERTY threat group (also known as Energetic Bear and Dragonfly).
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Russian government-sponsored threat actors have been linked to widespread router compromise campaigns in the past... The example from the Secureworks engagement appears to demonstrate how targeted threat groups such as IRON LIBERTY can weaponize their access to routers and Internet infrastructure to gain initial access to targeted systems.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
Analysis of the environment suggests that the most likely scenario was that the threat actor used man-on-the-side techniques to intercept the Adobe installer request when it transited a compromised router outside of the victim organization and then return the trojanized response.
The chaining or combination of multiple legacy vulnerability exploits with exploitation of the newer Windows Zerologon vulnerability
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
07:38:51-07:38:52 — The executed Karagany malware creates relevant directories and copies set170.exe as SearchIndexer.exe to the hard-coded %APPDATA%\Local\SearchIndexer\ installation directory.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
This type of rounding can indicate manually altered timestamps (also known as timestomping).
Analysis of the environment suggests that the most likely scenario was that the threat actor used man-on-the-side techniques to intercept the Adobe installer request when it transited a compromised router outside of the victim organization and then return the trojanized response.
Multiple malware families are described as identifying/enumerating open windows or capturing foreground window titles (e.g., via EnumWindows, GetForegroundWindow, GetWindowText) to understand user activity and provide context for keylogging/screencapture.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
The malware contains a large block of Base64-encoded data... After stepping over the Decode function... this section will populate with the decoded and then decrypted data... it uses the WriteFile call to write the decoded executable to this location. The StartA function then issues a system command to run this.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Karagany is malware used by the IRON LIBERTY espionage group. In this incident, it was delivered via a trojanized Adobe Flash installer in a likely man-on-the-side attack, then installed itself under %APPDATA%\Local\SearchIndexer\ as SearchIndexer.exe and established persistence via the Startup folder. The content notes the original Karagany malware was an e-crime tool later adopted and evolved by IRON LIBERTY.
Referenced as a possible secondary payload/backdoor that Goodor may have delivered to victims.
Secondary payload used post-compromise to steal credentials, capture screenshots, and transfer files, communicating with Dragonfly-associated C2 infrastructure.
Trojan capable of stealing data and credentials from browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.