Dragos identified STIBNITE as an intrusion group targeting government and industrial organizations in Azerbaijan, including wind generation entities, in operations spanning late 2019 through 2020. The activity focused on early-stage compromise in IT environments rather than confirmed operational disruption, with attackers seeking initial access, credential theft, and network reconnaissance that could later enable movement toward ICS and OT networks. Dragos linked the campaign to regional geopolitical tensions and noted the targeting as unusual because the Caucasus has seen comparatively limited public reporting on ICS-focused intrusions.
The group used spoofed Azerbaijani government credential-harvesting sites, spearphishing emails carrying malicious Microsoft Office documents, and the custom PoetRAT malware for collection and remote command execution. Cisco Talos separately documented PoetRAT using COVID-19-themed lures against Azerbaijan’s public and private sectors, reinforcing the malware’s role in the campaign. Additional tooling included PypyKatz and LaZagne for credential theft, while command-and-control infrastructure relied on DDNS-backed services and reused infrastructure across multiple 2020 operations.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Dragos disclosed STIBNITE as one of four new ICS/OT threat activity groups in its ICS Cybersecurity 2020 Year in Review reporting. The company said the group had targeted Azerbaijani government and wind generation organizations and was explicitly attempting to gain access to ICS networks and operations.
Cisco Talos reported a PoetRAT campaign using COVID-19-themed lures to target public and private sector entities in Azerbaijan. Dragos later associated PoetRAT with STIBNITE's intrusion activity.
Dragos found that STIBNITE reused infrastructure across its campaigns during 2020, alongside use of credential theft sites, spearphishing, PoetRAT, PypyKatz, and LaZagne. The activity remained concentrated in IT environments, though Dragos assessed it could support later ICS compromise.
Dragos reported that STIBNITE conducted multiple intrusion operations beginning in late 2019 against government and wind generation entities in Azerbaijan. The activity focused on initial access, credential theft, and information gathering consistent with Stage 1 of the ICS Cyber Kill Chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.