FORENSIA

THREAT_ACTOR · G0035

Dragonfly

Also known as: Dragonfly, TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE

Profile

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.

MITRE ATT&CK ↗

Techniques

56 ATT&CK techniques attributed to this actor.

T1003.002 Security Account ManagerT1003.003 NTDST1003.004 LSA SecretsT1005 Data from Local SystemT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1033 System Owner/User DiscoveryT1036.010 Masquerade Account NameT1053.005 Scheduled TaskT1059 Command and Scripting InterpreterT1059.001 PowerShellT1059.003 Windows Command ShellT1059.006 PythonT1069.002 Domain GroupsT1070.004 File DeletionT1071.002 File Transfer ProtocolsT1074.001 Local Data StagingT1078 Valid AccountsT1083 File and Directory DiscoveryT1087.002 Domain AccountT1098.007 Additional Local or Domain GroupsT1105 Ingress Tool TransferT1110 Brute ForceT1110.002 Password CrackingT1112 Modify RegistryT1113 Screen CaptureT1114.002 Remote Email CollectionT1133 External Remote ServicesT1135 Network Share DiscoveryT1136.001 Local AccountT1187 Forced AuthenticationT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1195.002 Compromise Software Supply ChainT1203 Exploitation for Client ExecutionT1204.002 Malicious FileT1210 Exploitation of Remote ServicesT1221 Template InjectionT1505.003 Web ShellT1547.001 Registry Run Keys / Startup FolderT1560 Archive Collected DataT1564.002 Hidden UsersT1566.001 Spearphishing AttachmentT1583.001 DomainsT1583.003 Virtual Private ServerT1584.004 ServerT1588.002 ToolT1591.002 Business RelationshipsT1595.002 Vulnerability ScanningT1598.002 Spearphishing AttachmentT1598.003 Spearphishing LinkT1608.004 Drive-by TargetT1685.005 Clear Windows Event LogsT1686 Disable or Modify System Firewall

Software

10 malware/tools attributed to this actor.

MimikatzPsExecNetRegBackdoor.OldreaTrojan.KaraganynetshImpacketCrackMapExecMCMD

Related corpus activity

10,026 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Dragonfly.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2022-47945cve851
cve-2021-4045cve851
cve-2020-22653cve852
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,026.