Dragonfly 2.0 is a malware/toolset associated with the Dragonfly intrusion activity and is documented here as operating on Windows hosts. Observed behavior includes modifying the Windows Registry via the Reg command-line utility to support multiple techniques, querying the Windows Registry to identify victim information, and executing the built-in command "query user" on victim systems for user discovery. It also performed screen capture collection from victims, including use of a tool named scr.exe that matched the hash of ScreenUtil. As part of operational cleanup and anti-forensics, Dragonfly 2.0 deleted numerous files used during operations, including removing applications and deleting screenshots. High-confidence indicators and artifacts mentioned in the content include the use of scr.exe/ScreenUtil for screenshots, the Reg utility for Registry modification, the "query user" command, and Registry querying for victim identification.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that queries the Windows Registry for victim/system identification data.
Intrusion set/tooling associated with screen capture activity (including scr.exe/ScreenUtil).
Modifies the Windows Registry (via reg.exe) to support multiple techniques.
Intrusion toolset/malware that performs post-operation cleanup by deleting operational files and artifacts (e.g., screenshots).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.