Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE
56
techniques
10
software
11,353
corpus matches
profile
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.
techniques
56 attributed · most-instrumented first
software
10 malware & tools attributed
Mimikatz
S0002
PsExec
S0029
Net
S0039
Reg
S0075
Backdoor.Oldrea
S0093
Trojan.Karagany
S0094
netsh
S0108
Impacket
S0357
CrackMapExec
S0488
MCMD
S0500
read this carefully
11,353 corpus matches is not attribution
That count is indicators which exhibit techniques Dragonfly is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+44 more techniques
showing 30 of 11,353
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.