Berserk Bear, also tracked as Dragonfly, Crouching Yeti, and IRON LIBERTY, has been linked by multiple organizations to Russian state-directed operations targeting enterprise and industrial control system environments. Reporting describes a long-running campaign focused on gaining and retaining privileged access inside critical infrastructure networks through spearphishing, drive-by compromises, exploitation of public-facing systems, and supply-chain compromises involving trojanized ICS software installers, followed by credential theft, administrator account creation, remote execution, and lateral movement using tools such as Mimikatz, PsExec, PowerShell, CrackMapExec, and SecretsDump.
The group increasingly shifted from exploit-led intrusions to credential-centric tradecraft, including malicious documents, strategic website compromise, outbound SMB authentication leakage, and WebDAV fallback behavior, then abused valid accounts, VPNs, OWA, RDP, and SMB to persist and move across victim environments. Researchers said the actors targeted technologies including Citrix, Microsoft Exchange, Fortinet VPNs, and Active Directory, exploiting vulnerabilities such as CVE-2019-19781, CVE-2020-0688, CVE-2018-13379, and CVE-2020-1472, while using compromised legitimate infrastructure to mask communications and quietly preposition access that could support future disruptive or coercive operations against critical infrastructure.

See the actors and campaigns active against you right now.
11 events from the most recent confirmed update back to the earliest known activity.
On July 20, 2021, the U.S. government updated the Havex ICS malware advisory to attribute the activity to Russian nation-state cyber actors. The update tied the earlier ICS-focused campaign, which used phishing, compromised websites, and trojanized ICS vendor installers, to Russian government-linked operators.
Gigamon states that no publicly known operations had been attributed to Berserk Bear since 2020. This marks the latest explicit activity boundary mentioned in the references.
The UK National Cyber Security Centre issued an advisory warning that hostile state actors had been compromising multiple UK organizations in the critical national infrastructure supply chain, especially engineering and industrial control companies. The notice said the activity had been ongoing since at least March 2017 and involved NTLM credential harvesting over SMB via strategic web compromises and spear-phishing.
US-CERT published alert TA18-074A describing Russian government cyber activity targeting the energy, nuclear, commercial facilities, water, aviation, and critical manufacturing sectors. The alert publicly documented the campaign and associated intrusion activity affecting critical infrastructure organizations.
Gigamon states that operations from 2018 to the present focused on maintaining steady and reliable access to valid credentials for remote access, lateral movement, and remote execution. The article describes use of harvested credentials, administrator account creation, password theft, and tools such as PSExec.
On 2017-10-20, DHS and the FBI issued technical alert TA17-293A describing an ongoing multi-stage intrusion campaign targeting organizations in the energy, nuclear, water, aviation, government, and critical manufacturing sectors. The alert said the activity had been underway since at least May 2017 and detailed use of supplier-network pivoting, spear-phishing, watering holes, credential harvesting, web shells, and ICS/SCADA reconnaissance.
Kaspersky ICS CERT reported that Energetic Bear compromised internet-facing servers during 2016 and early 2017 and used some of them as waterhole infrastructure against energy and industrial targets. The report described SMB-based credential harvesting via injected file:// links, web shells, and a backdoored sshd on affected servers across multiple countries.
Gigamon says the Dragonfly campaign used exploits across multiple intrusion vectors from at least 2010 through 2014. MITRE also describes Dragonfly using exploitation, watering holes, and supply-chain compromises in energy and ICS targeting.
Gigamon states Berserk Bear has operated since at least 2010. The same source places the Dragonfly campaign's exploit-based intrusion activity beginning in 2010.
A WIRED article published on October 26, 2020 described Berserk Bear as having gained access to US critical infrastructure, at times with hands-on-the-switches access, while stopping short of destructive sabotage. The piece framed that access as prepositioning to hold infrastructure at risk.
After the Dragonfly period, Gigamon says the group returned with strategic website compromise and phishing campaigns that emphasized leaking credentials from victim machines rather than relying primarily on exploits for initial access. MITRE likewise describes spearphishing, template injection, and SMB-based credential harvesting techniques.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
11 references tracked. Mallory keeps watching after this page renders.
blog.gigamon.com
Open sourceus-cert.cisa.gov
Open sourcesecurelist.com
Open sourcesymantec.com
Open sourceus-cert.cisa.gov
Open sourceattack.mitre.org
Open sourcearstechnica.com
Open sourcesecureworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.