U.S. government and private-sector reporting tied a malware family used in intrusions against energy and other critical infrastructure organizations to the Russian-linked Energetic Bear/Dragonfly activity set. A CERT/CC reverse-engineering review of a YARA rule published in CISA Alert TA17-293A found the signature was not a simple string match but a Windows API hashing routine used for manual symbol resolution, allowing the malware to locate kernel32.dll through the TEB/PEB and resolve functions such as VirtualProtect while hindering static analysis.
Using FLARE tooling alongside CERT/CC's own API hashing and UberFLIRT analysis, researchers identified the hashing method as sll1Add, built refined YARA detections, and found 37 related malware exemplars in CERT's MASS repository across 32-bit and 64-bit variants. The samples shared consistent kernel32.dll hashes, with additional ws2_32.dll and wininet.dll hashes indicating networking capability; analysts also recovered 29 unique IP:port indicators from 33 samples and reconstructed HTTP POST traffic from four others carrying headers including X-mode: push and X-mode: pop. A later update linked the tooling to Symantec's Trojan.Heriplor from Dragonfly reporting, strengthening the association with Energetic Bear and indicating the malware remained in active use.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
In fall 2018, the CERT Coordination Center Reverse Engineering Team received a tip about a YARA rule from TA17-293A that was triggering on VirusTotal samples allegedly associated with Energetic Bear. This prompted deeper reverse-engineering of an initial exemplar.
US-CERT released alert TA17-293A describing advanced persistent threat activity targeting energy and other critical infrastructure sectors and associating the activity with Russian-linked operations. A YARA rule from this alert later became the basis for CERT/CC's reverse-engineering analysis.
The reverse-engineering work led to API hashing being added to the MITRE MAEC Malware Behavior Catalog as a method under anti-static-analysis executable code obfuscation. This reflected formal recognition of the technique documented in the analysis.
A later update reported that Matt Brooks of Citizen Lab linked the analyzed API hashing tool to Symantec's Trojan.Heriplor described in Dragonfly reporting. This strengthened the association between the tooling and the Energetic Bear/Dragonfly threat group.
From the identified exemplars, CERT/CC extracted 29 unique IP-and-port pairs from 33 samples and reconstructed outbound HTTP POST traffic from four others. Observed traffic included headers such as "X-mode: push," "X-mode: pop," and "X-type: more" or "X-type: last."
Using refined YARA rules covering 32-bit, variant, and 64-bit implementations of the hashing routine, CERT/CC searched its MASS repository and ultimately identified 37 exemplars using the sll1Add API hashing method. Analysis showed consistent kernel32.dll hashes and additional ws2_32.dll or wininet.dll hashes indicating network capability.
CERT/CC determined that the YARA rule's key string matched a Windows API hashing routine rather than a simple string signature. The team linked the routine to a method similar to FireEye FLARE's sll1AddHash32 and showed the malware used manual symbol resolution through the TEB/PEB to locate kernel32.dll and resolve APIs such as VirtualProtect.
Symantec published reporting on the Dragonfly threat group, describing cyber attacks targeting the Western energy sector. This reporting later became relevant to linking the analyzed API hashing tool to Symantec's Trojan.Heriplor/Dragonfly activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
insights.sei.cmu.edu
Open sourceus-cert.gov
Open sourcesymantec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.